A VBScript campaign distributed through WhatsApp deploying RMM software

2026-06-23T08:51:55Zcbab10b83103c79e27c2f056852a62c2922fbf776dc8a36898672753e1b1a064
argamalci-cdcloud-atlascontainer-escapeexiftoolexposed-secretshentai-gamesmacosmalicious-wallpapersmobile-threatspowercloudprivilege-misconfigratreverse-socksrmmsparkcatsshsteam-workshopsupply-chain-attacktoruemsvbswardrivingwhatsappwifi-security

What happened

Kaspersky published multiple mid-2026 investigations covering diverse active threats and defensive gaps: a global campaign distributing VBS via WhatsApp that ultimately deploys a UEMS RMM agent through a multi-stage chain; dozens of malicious Steam Workshop wallpapers used to compromise gamers (notably in China and Russia); Argamal RAT distributed in infected hentai games; a wardriving assessment ahead of the 2026 World Cup highlighting exposed Wi‑Fi hotspots and configuration issues; analyses of container attack vectors including escapes, exposed secrets, privilege misconfigurations and CI/CD

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
cbab10b83103c79e27c2f056852a62c2922fbf776dc8a36898672753e1b1a064
Enrichment time
2026-06-23T08:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.