A VBScript campaign distributed through WhatsApp deploying RMM software
2026-06-23T08:51:55Z•cbab10b83103c79e27c2f056852a62c2922fbf776dc8a36898672753e1b1a064
argamalci-cdcloud-atlascontainer-escapeexiftoolexposed-secretshentai-gamesmacosmalicious-wallpapersmobile-threatspowercloudprivilege-misconfigratreverse-socksrmmsparkcatsshsteam-workshopsupply-chain-attacktoruemsvbswardrivingwhatsappwifi-security
What happened
Kaspersky published multiple mid-2026 investigations covering diverse active threats and defensive gaps: a global campaign distributing VBS via WhatsApp that ultimately deploys a UEMS RMM agent through a multi-stage chain; dozens of malicious Steam Workshop wallpapers used to compromise gamers (notably in China and Russia); Argamal RAT distributed in infected hentai games; a wardriving assessment ahead of the 2026 World Cup highlighting exposed Wi‑Fi hotspots and configuration issues; analyses of container attack vectors including escapes, exposed secrets, privilege misconfigurations and CI/CD
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- cbab10b83103c79e27c2f056852a62c2922fbf776dc8a36898672753e1b1a064
- Enrichment time
- 2026-06-23T08:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.