ToddyCat: your hidden email assistant. Part 2

2026-07-01T08:51:54Zd3909cdaaf98edd2d44909cb8d096cb384181909b45291837b3fedb68d69bf51
ArgamalCobalt StrikeGmailGoogle servicesOAuth token theftRATRaaSSMB threatsSharkLoaderSteam WorkshopStrikeSharkThe GentlemenToddyCatUEMS RMMUmbrijVBScriptWhatsAppWi-Fi securitycontainer securityfake AI toolsmalicious wallpapersphishingransomwaresupply chain attackswardriving

What happened

This Securelist collection highlights multiple active threats and shifting tactics across 2026: ToddyCat’s Umbrij tool abuses OAuth tokens to compromise Gmail/Google services; The Gentlemen RaaS group has evolved with custom backdoors and a new ransomware variant; a global StrikeShark campaign delivers Cobalt Strike via custom SharkLoader; a WhatsApp-distributed VBS campaign installs UEMS RMM agents; dozens of malicious Steam Workshop wallpapers are being used to compromise gamers; Argamal RAT is being distributed via infected hentai games; wardriving assessments ahead of the 2026 FIFA World C

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
d3909cdaaf98edd2d44909cb8d096cb384181909b45291837b3fedb68d69bf51
Enrichment time
2026-07-01T08:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.