Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools

2026-06-27T08:51:52Zc83a701d0813fbe4c03d002f0a3467874cf84b37a1c5de00c975609b7bdc9f24
argamalcloud_atlascobalt_strikecontainer_securitycontainersfake_ai_toolsmalicious_wallpapersmalwarephishingpowercloudratreverse_socksrmmsharkloadersmbsshsteam_workshopstrikesharksupply_chain_attackstoruemsvbscriptwardrivingwhatsappwifi_security

What happened

Kaspersky Securelist published a set of June 2026 reports describing a diverse, active threat landscape affecting SMBs and consumers: increased phishing and scams (including fake AI tools), multiple malware campaigns delivering Cobalt Strike Beacon via a custom SharkLoader (StrikeShark), a WhatsApp-distributed VBScript campaign installing a UEMS RMM agent, and Argamal RAT distributed with pirated hentai games. Researchers also found malicious Steam Workshop wallpapers being used to compromise gamers, ongoing piracy-related campaigns that added RAT/miner modules, and targeted APT activity ("Сlо

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
c83a701d0813fbe4c03d002f0a3467874cf84b37a1c5de00c975609b7bdc9f24
Enrichment time
2026-06-27T08:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools · Baitaphish