Securelist
Argamal Malware Campaign Targets Hentai Game Players Worldwide
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In April 2026, Kaspersky discovered a new malware campaign named Argamal, targeting players of hentai games. This Remote Access Trojan (RAT) compromises systems by installing a malicious implant that later downloads a Trojan, granting attackers full control. The malware has been detected in multiple countries, including Russia, Brazil, and Germany. Distribution occurs through infected game downloads from websites and torrent trackers like AniRena, often disguised as legitimate game files. The malware employs COM hijacking for persistence and uses modified DLLs to execute malicious scripts. Kaspersky has identified various delivery methods, including embedding malicious payloads directly within game files. The campaign is ongoing, with the malware being actively updated. Users are advised to avoid downloading games from unverified sources.
Key Points: • Argamal is a new RAT targeting players of hentai games, allowing full system compromise. • The malware is distributed via infected game downloads from websites and torrent trackers. • Kaspersky has detected Argamal in multiple countries, indicating a widespread impact.