ToddyCat: your hidden email assistant. Part 2
2026-07-01T08:51:54Z•d3909cdaaf98edd2d44909cb8d096cb384181909b45291837b3fedb68d69bf51
ArgamalCobalt StrikeGmailGoogle servicesOAuth token theftRATRaaSSMB threatsSharkLoaderSteam WorkshopStrikeSharkThe GentlemenToddyCatUEMS RMMUmbrijVBScriptWhatsAppWi-Fi securitycontainer securityfake AI toolsmalicious wallpapersphishingransomwaresupply chain attackswardriving
What happened
This Securelist collection highlights multiple active threats and shifting tactics across 2026: ToddyCat’s Umbrij tool abuses OAuth tokens to compromise Gmail/Google services; The Gentlemen RaaS group has evolved with custom backdoors and a new ransomware variant; a global StrikeShark campaign delivers Cobalt Strike via custom SharkLoader; a WhatsApp-distributed VBS campaign installs UEMS RMM agents; dozens of malicious Steam Workshop wallpapers are being used to compromise gamers; Argamal RAT is being distributed via infected hentai games; wardriving assessments ahead of the 2026 FIFA World C
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- d3909cdaaf98edd2d44909cb8d096cb384181909b45291837b3fedb68d69bf51
- Enrichment time
- 2026-07-01T08:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.