{"id":3471,"date":"2026-06-03T10:03:58","date_gmt":"2026-06-03T10:03:58","guid":{"rendered":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/"},"modified":"2026-06-03T10:03:58","modified_gmt":"2026-06-03T10:03:58","slug":"argamal-malware-hidden-in-hentai-games","status":"publish","type":"post","link":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/","title":{"rendered":"Argamal: Malware hidden in hentai games"},"content":{"rendered":"<div>\n<p><img width=\"990\" height=\"400\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg\" class=\"attachment-securelist-huge-promo size-securelist-huge-promo wp-post-image\" alt=\"\" decoding=\"async\" loading=\"lazy\"><\/p>\n<p>In April 2026, we discovered a new malware campaign targeting players of \u201chentai\u201d games. Once launched, the infected games install a previously unknown malicious implant on the user\u2019s machine. After a few days, the implant downloads and executes a Trojan, resulting in full system compromise and broad remote control capabilities for the attackers. We dubbed this malware family \u201cArgamal\u201d.<\/p>\n<p>The malware uses COM hijacking to persist on the victim\u2019s machine, replacing the <code>InprocServer32<\/code> entry for Windows Color System Calibration Loader DLL. This task is triggered when the user logs in, effectively allowing the malware to run at startup.<\/p>\n<p>Kaspersky solutions detect this threat as <code>Trojan.Win32.Termixia.*<\/code>, <code>Trojan.Win32.Agent.*<\/code>, <code>HEUR:Trojan.Win32.Argamal.gen<\/code> and <code>HEUR:Trojan-Downloader.Win32.Argamal.gen<\/code>.<\/p>\n<h2 id=\"technical-details\">Technical details<\/h2>\n<h3 id=\"background\">Background<\/h3>\n<p>In April, as part of our ongoing monitoring of telemetry data, we found some suspicious DLLs. Further analysis revealed that various versions of these DLLs have existed since at least 2024.<\/p>\n<p>The DLLs were spawned by different games written using various game engines and programming languages, including RenPy (Python) and RPG Maker MV (JavaScript), among others. However, they all had one thing in common: they were all hentai games. We searched for the distribution sources and found a number of websites hosting game screenshots and download links. These links redirected users to PixelDrain, a free file transfer service.<\/p>\n<div id=\"attachment_120000\" style=\"width: 1755px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1.png\" class=\"magnificImage\"><img fetchpriority=\"high\" decoding=\"async\" aria-describedby=\"caption-attachment-120000\" class=\"size-full wp-image-120000\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1.png\" alt=\"Adult games catalogue\" width=\"1745\" height=\"876\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1.png 1745w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1-300x151.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1-1024x514.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1-768x386.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1-1536x771.png 1536w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1-697x350.png 697w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1-740x371.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1-558x280.png 558w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183710\/argamal-rat1-800x402.png 800w\" sizes=\"(max-width: 1745px) 100vw, 1745px\"><\/a><\/p>\n<p id=\"caption-attachment-120000\" class=\"wp-caption-text\">Adult games catalogue<\/p>\n<\/div>\n<p>In addition to these websites, the trojanized games have also been distributed via different torrent trackers, including AniRena.<\/p>\n<div id=\"attachment_120001\" style=\"width: 2058px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120001\" class=\"size-full wp-image-120001\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2.png\" alt=\"Malicious game torrent in AniRena\" width=\"2048\" height=\"450\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2.png 2048w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2-300x66.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2-1024x225.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2-768x169.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2-1536x338.png 1536w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2-1593x350.png 1593w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2-740x163.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2-1274x280.png 1274w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183751\/argamal-rat2-800x176.png 800w\" sizes=\"auto, (max-width: 2048px) 100vw, 2048px\"><\/a><\/p>\n<p id=\"caption-attachment-120001\" class=\"wp-caption-text\">Malicious game torrent in AniRena<\/p>\n<\/div>\n<h3 id=\"delivery\">Delivery<\/h3>\n<p>Both the dedicated websites and torrents delivered an archive containing the infected game.<\/p>\n<div id=\"attachment_120002\" style=\"width: 920px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183829\/argamal-rat3.jpg\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120002\" class=\"size-full wp-image-120002\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183829\/argamal-rat3.jpg\" alt=\"Contents of the game archive\" width=\"910\" height=\"1280\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183829\/argamal-rat3.jpg 910w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183829\/argamal-rat3-213x300.jpg 213w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183829\/argamal-rat3-728x1024.jpg 728w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183829\/argamal-rat3-768x1080.jpg 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183829\/argamal-rat3-249x350.jpg 249w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183829\/argamal-rat3-711x1000.jpg 711w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183829\/argamal-rat3-199x280.jpg 199w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29183829\/argamal-rat3-640x900.jpg 640w\" sizes=\"auto, (max-width: 910px) 100vw, 910px\"><\/a><\/p>\n<p id=\"caption-attachment-120002\" class=\"wp-caption-text\">Contents of the game archive<\/p>\n<\/div>\n<p>This archive contained fully functional, legitimate game files, as well as a modified FFmpeg DLL (SHA1: <code>42add9475e67a1ccc6a6af94b5475d3defc01b85<\/code>), that imported the <code>DllGetClassObject<\/code> function from a file called <code>natives2_blob.bin<\/code>. Since the game needs <code>ffmpeg.dll<\/code> to run properly, the library loads as soon as the user starts the game.<\/p>\n<h3 id=\"script-executor\">Script executor<\/h3>\n<p>The <code>natives2_blob.bin<\/code> (SHA1: <code>edce72f59e4c1d136cd1946af70d334c19df858d<\/code>) file is a DLL that executes a Base64-encoded PowerShell script when loaded.<\/p>\n<div id=\"attachment_120003\" style=\"width: 1084px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184048\/argamal-rat4.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120003\" class=\"size-full wp-image-120003\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184048\/argamal-rat4.png\" alt=\"The natives2_blob.bin file code\" width=\"1074\" height=\"291\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184048\/argamal-rat4.png 1074w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184048\/argamal-rat4-300x81.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184048\/argamal-rat4-1024x277.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184048\/argamal-rat4-768x208.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184048\/argamal-rat4-740x201.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184048\/argamal-rat4-1033x280.png 1033w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184048\/argamal-rat4-800x217.png 800w\" sizes=\"auto, (max-width: 1074px) 100vw, 1074px\"><\/a><\/p>\n<p id=\"caption-attachment-120003\" class=\"wp-caption-text\">The natives2_blob.bin file code<\/p>\n<\/div>\n<p>This PowerShell script, which we\u2019ll call <code>Stage1<\/code>, performs basic checks for controlled environments. For example, it checks for the Sandboxie folder in Program Files and Procmon64 in the process list. If all the checks indicate that the process is not running in a controlled environment, it proceeds to establish persistence.<\/p>\n<p><code>Stage1<\/code> sets the <code>MI_V<\/code> environment variable (and also <code>MI_V2<\/code> in the new versions of malware) for the current user to another Base64-encoded PowerShell script, which we\u2019ll call <code>Stage2<\/code>. After that, it sets the <code>InprocServer32<\/code> registry key at <code>HKCUSOFTWAREClassesCLSID{722D0F89-B69C-4700-AE8C-4A44350E4876}<\/code> to a random DLL file name in a random subdirectory of <code>%USER%AppDataLocal<\/code>, as well as the <code>ShellFolder<\/code> subkey to another random DLL file name in the same location. <code>Stage1<\/code> also creates a scheduled task that will execute three days later. This task executes <code>Stage2<\/code> and runs once.<\/p>\n<p><code>Stage2<\/code> is a payload downloader script. It takes previously generated DLL filenames from the registry and downloads an encrypted payload called <code>zaesdl.dat<\/code> from GitHub using <code>bitsadmin.exe<\/code>. The downloaded payload is saved in the <code>settings.dat<\/code> file in the randomly chosen subdirectory of <code>%USER%AppDataLocal<\/code>. <code>Stage2<\/code> decrypts it using AES-CBC with the key <code>zbcd1j9234r670eh<\/code> and an IV equal to the key. The decrypted payload is then saved in the DLL file specified in the <code>ShellFolder<\/code> registry subkey.<\/p>\n<p>The decrypted payload is set as <code>InprocServer32<\/code> at <code>HKCUSOFTWAREClassesCLSID{B210D694-C8DF-490D-9576-9E20CDBC20BD}<\/code>, which is a COM object used by the <code>MicrosoftWindowsWindowsColorSystemCalibration<\/code> Loader scheduled task. This task runs every time a user logs in, allowing the malware to run during every user session.<\/p>\n<p>Before quitting, Stage2 also removes the changes made under the <code>HKCUSOFTWAREClassesCLSID{722D0F89-B69C-4700-AE8C-4A44350E4876}<\/code> registry key, unsets the <code>MI_V<\/code> environment variable (and MI_V2 in newer versions), and removes the scheduled task that launched <code>Stage2<\/code>.<\/p>\n<h3 id=\"malicious-agent\">Malicious agent<\/h3>\n<p>Early payload versions decrypted themselves using the <code>0xB0C1D4E9<\/code> rolling XOR key, where the decryption key for the <code>i + 1<\/code> block is the encrypted content of the <code>i<\/code> block (each encrypted block being four bytes long). The most recent agent versions don\u2019t do that.<\/p>\n<p>The samples we found had string encryption; they use a simple substitution with a key that corresponds position-by-position to the following alphabet: <code>ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789@#$.\/:&lt;&gt;*&amp;~<\/code>. The decryption process involves finding the position of each symbol of the encrypted strings in the key, and replacing it with the symbol that occupies the same position in the alphabet.<br \/>\nDuring our investigation, we found the following keys were used:<\/p>\n<ul>\n<li>17htUno\/I3L&amp;fK2H#yapE@b5NqZ$Q4xmeF.s96uB&gt;jkdWCPvAgD*XwO:iR~TMrV0YGl8z&lt;JSc<\/li>\n<li>71htUno\/I3L&amp;fK2H#aypE@b5NqZ$Q4xmeF.s96uB&gt;jdkWCPvAgD*XwO:iR~TMrV0YGl8z&lt;JSc<\/li>\n<li>E1hUtno\/IL3&amp;fK2H#ypa7@b5NqZ$Q4xmeF.s69uB&gt;jkdWCvPAgD*XwO:iR~TrMV0YGl8z&lt;JcS<\/li>\n<\/ul>\n<p>All symbols not used in the key remain unchanged.<\/p>\n<div id=\"attachment_120004\" style=\"width: 961px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184706\/argamal-rat5.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120004\" class=\"size-full wp-image-120004\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184706\/argamal-rat5.png\" alt=\"String decryption\" width=\"951\" height=\"418\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184706\/argamal-rat5.png 951w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184706\/argamal-rat5-300x132.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184706\/argamal-rat5-768x338.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184706\/argamal-rat5-796x350.png 796w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184706\/argamal-rat5-740x325.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184706\/argamal-rat5-637x280.png 637w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184706\/argamal-rat5-800x352.png 800w\" sizes=\"auto, (max-width: 951px) 100vw, 951px\"><\/a><\/p>\n<p id=\"caption-attachment-120004\" class=\"wp-caption-text\">String decryption<\/p>\n<\/div>\n<p>The payload checks for the presence of the following security solutions using the output of the <code>tasklist<\/code> command:<\/p>\n<ul>\n<li>Kaspersky<\/li>\n<li>Avast<\/li>\n<li>McAfee<\/li>\n<li>BitDefender<\/li>\n<li>MalwareBytes<\/li>\n<li>+36 other solutions<\/li>\n<\/ul>\n<div id=\"attachment_120005\" style=\"width: 832px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184741\/argamal-rat6.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120005\" class=\"size-full wp-image-120005\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184741\/argamal-rat6.png\" alt=\"Security solution detection logic\" width=\"822\" height=\"270\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184741\/argamal-rat6.png 822w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184741\/argamal-rat6-300x99.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184741\/argamal-rat6-768x252.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184741\/argamal-rat6-740x243.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29184741\/argamal-rat6-800x263.png 800w\" sizes=\"auto, (max-width: 822px) 100vw, 822px\"><\/a><\/p>\n<p id=\"caption-attachment-120005\" class=\"wp-caption-text\">Security solution detection logic<\/p>\n<\/div>\n<p>The payload itself is a RAT with broad functionality. The default C2 server is <code>asper1[.]freeddns[.]org<\/code> for earlier versions and <code>Winst0[.]kozow[.]com<\/code> for the latest versions of the payload. Both domains point to <code>186[.]158.223.35<\/code>. We also saw another IP address for the first C2 in pDNS records, though we haven\u2019t actually seen it in use. The C2 address can change based on a C2 reply or when certain conditions are met. For example, if the user\u2019s default locale is set to \u201czh-CN\u201d, the RAT sets its C2 address to <code>country1[.]ignorelist[.]com<\/code>. During most of our investigation, this domain pointed to <code>127[.]0.0.1<\/code>, but starting April 26, it has been pointing to <code>186[.]158.223.35<\/code> as well.<\/p>\n<p>The payload sends UDP heartbeats to port 57441 of the C2 server. These heartbeats contain information about detected security solutions, system startup time, time since last input activity, architecture info, machine IP address and username.<\/p>\n<p>The C2 may respond to the heartbeat. Based on this response, the payload can perform different actions. Below is the full list of available commands.<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>Response first byte<\/strong><\/td>\n<td><strong>Description<\/strong><\/td>\n<\/tr>\n<tr>\n<td>0x31<\/td>\n<td>Run DLL on the system<\/td>\n<\/tr>\n<tr>\n<td>0x57<\/td>\n<td>Send UDP request to the specified address<\/td>\n<\/tr>\n<tr>\n<td>0x55<\/td>\n<td>Open file or link from the response<\/td>\n<\/tr>\n<tr>\n<td>0x50<\/td>\n<td>Collect information about the infected system (e.g. process list and architecture)<\/td>\n<\/tr>\n<tr>\n<td>0x53<\/td>\n<td>Execute command from the response using ShellExecuteW<\/td>\n<\/tr>\n<tr>\n<td>0x52<\/td>\n<td>Run the file specified in the response using WinExec<\/td>\n<\/tr>\n<tr>\n<td>0x42<\/td>\n<td>Delete the file specified in the response<\/td>\n<\/tr>\n<tr>\n<td>0x41<\/td>\n<td>Update C2 domain<\/td>\n<\/tr>\n<tr>\n<td>0x59<\/td>\n<td>Get new payload: connect to C2 port 63559\/UDP, get new DLL and update COM path in the registry<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>The C2 can also set a flag in the response that will turn on the extended RAT mode. In this mode, the payload communicates with the C2 server using the 3747\/tcp port.<\/p>\n<p>TCP communications are encrypted using a simple substitution cipher. Each character is replaced using a fixed mapping defined by the key:<\/p>\n<pre class=\"urvanov-syntax-highlighter-plain-tag\">koP]Y4Os-_t?cB',aK.Wm&gt;QM2[U!^C`*@Ff:X6Dp8H%ATydE&lt;e(#G&amp;LhwRZ5znjJqgNrl)I7V$3=910\"+Svxi\/;ub<\/pre>\n<p>This key corresponds position-by-position to the standard ASCII character sequence:<\/p>\n<pre class=\"urvanov-syntax-highlighter-plain-tag\">!\"#$%&amp;'()*+,-.\/0123456789:;&lt;=&gt;?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\\]^_`abcdefghijklmnopqrstuvwxyz{|}<\/pre>\n<p>In other words, each character in the ASCII set is replaced by the corresponding character in the key string.<\/p>\n<p>C2 requests and responses are divided into two parts by the first space character. The first part is a command and the second part is usually an argument.<br \/>\nAfter connecting and before receiving information from the C2, the malware sends metadata about the infected machine using the <code>NOOP<\/code> command. This metadata includes a run cycle counter, mounted drive metadata, time since the last input activity and data about the display settings.<\/p>\n<p>Based on the C2 command, the malware can execute commands on the infected machine, perform reboot and shutdown actions, control the cursor, take screenshots, compress files into archives, and send files to other specified servers. In short, it can fully control the machine. The full list of commands is as follows:<\/p>\n<p><strong>System control<\/strong><\/p>\n<ul>\n<li><code>KILL REBOOT<\/code>: Reboots the infected system<\/li>\n<li><code>KILL POWER<\/code>: Shuts down the infected system<\/li>\n<li><code>KILL SELF<\/code>: Same as the QUIT command (described below)<\/li>\n<li><code>KILL ME<\/code>: Exits process running the malware<\/li>\n<\/ul>\n<p><strong>Surveillance<\/strong><\/p>\n<ul>\n<li><code>SCREEN<\/code> \/ <code>SCREEN9<\/code>: makes a screenshot, saves it to the ~wra1269.tmp file and sends it to the C2<\/li>\n<\/ul>\n<p><strong>File operations<\/strong><\/p>\n<ul>\n<li><code>DELETE &lt;filename&gt;<\/code>: deletes specified file<\/li>\n<li><code>DELDIR &lt;dirname&gt;<\/code>: deletes specified directory<\/li>\n<li><code>REN &lt;file path 1&gt;#&lt;file path 2&gt;<\/code>: moves specified file<\/li>\n<li><code>MAKDIR &lt;path&gt;<\/code>: creates directory<\/li>\n<li><code>ZIPFILE &lt;file or folder name&gt;<\/code> \/ <code>ZIPFOLDER &lt;file or folder name&gt;<\/code>: compresses specified file\/folder into a <code>.zip<\/code> archive<\/li>\n<li><code>TAR &lt;file or folder name&gt;<\/code> \/ <code>TAR2 &lt;file or folder name&gt;<\/code>: compresses specified file\/folder into a .tar archive<\/li>\n<li><code>GETFILEDATE &lt;filename&gt;<\/code>: sends file\u2019s last modification date<\/li>\n<li><code>SETFILEDATE &lt;filename&gt;<\/code>: sets file\u2019s last modification date<\/li>\n<li><code>GETFILEACC &lt;filename&gt;<\/code>: sends file\u2019s last access date<\/li>\n<li><code>DWLOAD &lt;filename&gt;<\/code>: sends file to the C2<\/li>\n<li><code>UPLOAD &lt;filename&gt;#&lt;C2 address&gt;<\/code>: uploads file to the specified C2 server<\/li>\n<\/ul>\n<p><strong>Reconnaissance<\/strong><\/p>\n<ul>\n<li><code>USER<\/code>: sends username<\/li>\n<li><code>KALIVE<\/code>: sends run cycle counter<\/li>\n<li><code>IDLE<\/code>: sends number of seconds passed since last input activity<\/li>\n<li><code>DRIVES<\/code>: sends information about mounted drives<\/li>\n<li><code>FOLDEX &lt;folder type&gt;<\/code>: sends full path to a directory of the specified type:<\/li>\n<li>\u2013 type = <code>0x63<\/code>: temporary directory<\/li>\n<li>\u2013 type = <code>0x64<\/code>: GoogleChromeUser DataDefault in AppDataLocal folder<\/li>\n<li>\u2013 type = <code>0x65<\/code>: Downloads in user home directory<\/li>\n<li>\u2013 type = <code>0x66<\/code>: MicrosoftExcelXLSTART in AppData folder<\/li>\n<li>\u2013 type = <code>0x67<\/code>: AppData folder<\/li>\n<li><code>LFILES &lt;folder path&gt;<\/code>: lists and sends paths to all files in the directory<\/li>\n<li><code>OSVER<\/code>: sends information about user, hostname, OS architecture and version<\/li>\n<li><code>COMPILERDATE<\/code>: sends constant hardcoded in the RAT, e.g., 25.10.2025<\/li>\n<\/ul>\n<p><strong>Generic control<\/strong><\/p>\n<ul>\n<li><code>DSOCKE<\/code>: recreates TCP keep-alive socket<\/li>\n<li><code>QUIT<\/code>: notifies the C2 about quitting, closes the socket and stops the process<\/li>\n<li><code>RUNHID &lt;command&gt;<\/code> \/ <code>RUN &lt;command&gt;<\/code>: runs specified command inside <code>ShellExecuteW<\/code><\/li>\n<li><code>RUNDOS &lt;command&gt;<\/code>: runs specified command inside CreateProcessW<\/li>\n<li><code>RUNTASK &lt;command&gt;<\/code>: creates, runs and deletes task that executes specified command<\/li>\n<li><code>SKEY &lt;key code&gt;<\/code>: presses specified key<\/li>\n<li><code>MOUSE FREEZE<\/code>: freezes mouse movement<\/li>\n<li><code>MOUSE &lt;command&gt;<\/code>: clicks the specified mouse button or sets the cursor position to the specified coordinates<\/li>\n<\/ul>\n<h3 id=\"other-delivery-methods\">Other delivery methods<\/h3>\n<p>During our research, we also observed other delivery methods for the RAT. Instead of patching FFmpeg and downloading the payload from GitHub, the attackers included the main payload as <code>libpython64.dat<\/code> or another file with a similar name in the <code>libpy3-windows-x86_64<\/code> directory of the game. This .dat file was loaded by one of the libraries used in the game, which was patched for this purpose.<\/p>\n<p>In another case, the threat actor posted their malicious DLL file (payload downloader) on a gaming forum, disguising it as a cheat.<\/p>\n<h2 id=\"infrastructure\">Infrastructure<\/h2>\n<p>Our research revealed the following infrastructure was used in this attack.<\/p>\n<table>\n<tbody>\n<tr>\n<td><strong>Domain<\/strong><\/td>\n<td><strong>IP<\/strong><\/td>\n<td><strong>First seen<\/strong><\/td>\n<td><strong>ASN<\/strong><\/td>\n<\/tr>\n<tr>\n<td>asper1[.]freeddns[.]org<\/td>\n<td>181[.]116.218.56<\/td>\n<td>September 16, 2024<\/td>\n<td>11664<\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td>186[.]158.223.35<\/td>\n<td>July 01, 2025<\/td>\n<td>11664<\/td>\n<\/tr>\n<tr>\n<td>country1[.]ignorelist[.]com<\/td>\n<td>186[.]158.223.35<\/td>\n<td>September 10, 2025<\/td>\n<td>11664<\/td>\n<\/tr>\n<tr>\n<td><\/td>\n<td>127[.]0.0.1<\/td>\n<td>November 11, 2025<\/td>\n<td>\u2013<\/td>\n<\/tr>\n<tr>\n<td>Winst0.kozow[.]com<\/td>\n<td>186[.]158.223.35<\/td>\n<td>April 26, 2026<\/td>\n<td>11664<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"victims\">Victims<\/h2>\n<p>According to our telemetry, hundreds of individuals were infected with this malware. The majority of the victims were located in Russia, Brazil, Germany and Vietnam.<\/p>\n<div class=\"js-infogram-embed\" data-id=\"_\/9jPuK5ZkjEP5YvroJELA\" data-type=\"interactive\" data-title=\"01 - EN  Argamal graph\" style=\"min-height:;\"><\/div>\n<\/p>\n<p><center><strong><em>Distribution of victims (<a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03064825\/01-en-argamal-graph.png\" target=\"_blank\">download<\/a>)<\/em><\/strong><\/center><\/p>\n<h2 id=\"attribution\">Attribution<\/h2>\n<p>Based on the language of the comments in the code, infrastructure data and other facts we assess with medium confidence that the developer of the downloader chain speaks Spanish.<\/p>\n<p>The actor behind this attack uses Spanish in variable names and comments. For example, the Base64-decoded delivery script contains the following lines:<\/p>\n<div id=\"attachment_120007\" style=\"width: 2058px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120007\" class=\"size-full wp-image-120007\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8.png\" alt=\"Part of the PowerShell script used in the payload delivery\" width=\"2048\" height=\"519\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8.png 2048w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8-300x76.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8-1024x260.png 1024w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8-768x195.png 768w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8-1536x389.png 1536w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8-1381x350.png 1381w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8-740x188.png 740w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8-1105x280.png 1105w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185839\/argamal-rat8-800x203.png 800w\" sizes=\"auto, (max-width: 2048px) 100vw, 2048px\"><\/a><\/p>\n<p id=\"caption-attachment-120007\" class=\"wp-caption-text\">Part of the PowerShell script used in the payload delivery<\/p>\n<\/div>\n<p>In addition, the JavaScript code from the website distributing infected games contains variable names, function names and comments in Spanish:<\/p>\n<div id=\"attachment_120008\" style=\"width: 561px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185908\/argamal-rat9.png\" class=\"magnificImage\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-120008\" class=\"size-full wp-image-120008\" src=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185908\/argamal-rat9.png\" alt=\"JavaScript code from the malicious site\" width=\"551\" height=\"501\" srcset=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185908\/argamal-rat9.png 551w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185908\/argamal-rat9-300x273.png 300w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185908\/argamal-rat9-385x350.png 385w, https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/05\/29185908\/argamal-rat9-308x280.png 308w\" sizes=\"auto, (max-width: 551px) 100vw, 551px\"><\/a><\/p>\n<p id=\"caption-attachment-120008\" class=\"wp-caption-text\">JavaScript code from the malicious site<\/p>\n<\/div>\n<p>Notably, the malware payloads used in this attack had previously chosen <code>127.0.0.1<\/code> as their C2 server when the victim\u2019s default locale is set to \u201czh-CN\u201d, thus not targeting Chinese users. This may indicate that the attacker is associated with a Chinese-speaking threat actor or uses payloads developed by a Chinese-speaking threat actor. However, we still believe it\u2019s unlikely that the developer of these delivery chains is Chinese-speaking.<\/p>\n<h2 id=\"conclusions\">Conclusions<\/h2>\n<p>The Argamal Trojan is a new RAT targeting individuals who seek adult games. During our analysis, we observed a steady stream of updates to the payload, including the addition of new features and fixes for various bugs, as well as changes to the infrastructure. This leads us to believe that the threat actor behind this malware will continue to develop and enhance it. The campaign\u2019s goal is likely data and credential theft; however, the RAT enables the attacker to take full control of the device and execute any malicious activity they want.<\/p>\n<p>Creating malware in today\u2019s development landscape has become significantly easier thanks to the wide availability of detailed guides, tooling, and automation resources. As a result, it is crucial not only to detect known malware but also to identify new and evolving threats as they emerge. Kaspersky solutions prevented the malicious activity in the earliest stages of the attack. The solutions help ensure device security by identifying not only known threats but also the behavior of the software and its actions, providing comprehensive protection against malware.<\/p>\n<h2 id=\"indicators-of-compromise\">Indicators of Compromise<\/h2>\n<p><strong>File hashes<\/strong><br \/>\nRAT payloads:<br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/76253fb55aed707440e808ea78e7101318436b1c\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_779ccfc7a77e0a90\" target=\"_blank\" rel=\"noopener\">76253fb55aed707440e808ea78e7101318436b1c<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/1405a3c5e0aeb08012484134e16cdec4ab29b4a4\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_55ae1d9eafb119b9\" target=\"_blank\" rel=\"noopener\">1405a3c5e0aeb08012484134e16cdec4ab29b4a4<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/535f4337f261b6da20a3c614eb13270bed2d533a\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_995b3244099ba368\" target=\"_blank\" rel=\"noopener\">535f4337f261b6da20a3c614eb13270bed2d533a<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/d2cb0d7a9ad2b5d4ea7c2da8aec62beb37cf36d6\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_067a619c17d6d92d\" target=\"_blank\" rel=\"noopener\">d2cb0d7a9ad2b5d4ea7c2da8aec62beb37cf36d6<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/e05f1767c2a337910ed75e90288838d6d0541164\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_3fe6bbe8ea5550aa\" target=\"_blank\" rel=\"noopener\">e05f1767c2a337910ed75e90288838d6d0541164<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/dad26f61da7b8bccc78364411812be74c025b475\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_cd6b2f3b55fe5c47\" target=\"_blank\" rel=\"noopener\">dad26f61da7b8bccc78364411812be74c025b475<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/29f1d346a6e71774c7dad25b90f446b2974393df\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_59745e224a51b855\" target=\"_blank\" rel=\"noopener\">29f1d346a6e71774c7dad25b90f446b2974393df<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/e815a9b418d09c2d4bcd074c2c0bc21406eeb22f\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_b9f13c5de0eb4d64\" target=\"_blank\" rel=\"noopener\">e815a9b418d09c2d4bcd074c2c0bc21406eeb22f<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/17f8f8f34dfa737f36182fed7ff9e9814a114058\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_f21b32012457cd36\" target=\"_blank\" rel=\"noopener\">17f8f8f34dfa737f36182fed7ff9e9814a114058<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/954722b0c9c678b1313d1f8b204e102842dc5889\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_971a1d0497d5c0c7\" target=\"_blank\" rel=\"noopener\">954722b0c9c678b1313d1f8b204e102842dc5889<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/69331cfdac792dc79240e6a6bb6e803eabd70beb\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_d0faa850ba1179a8\" target=\"_blank\" rel=\"noopener\">69331cfdac792dc79240e6a6bb6e803eabd70beb<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/901cfa97b1baaf908fd4a02bb52d970f576c4193\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_8860028e6fa41707\" target=\"_blank\" rel=\"noopener\">901cfa97b1baaf908fd4a02bb52d970f576c4193<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/5f1f3689bcf23de1b280b5f35712946da0f7978f\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_981b20e0db22128e\" target=\"_blank\" rel=\"noopener\">5f1f3689bcf23de1b280b5f35712946da0f7978f<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/c2d9d48b3b10bd58cdf5df9463e3ffcd60533ff3\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_8da7d409ea67d2d3\" target=\"_blank\" rel=\"noopener\">c2d9d48b3b10bd58cdf5df9463e3ffcd60533ff3<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/2423a5bf0fa7cb9ec09211630a5488629499691b\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_ef0a32284cd8f80b\" target=\"_blank\" rel=\"noopener\">2423a5bf0fa7cb9ec09211630a5488629499691b<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/ae4601a19d28332a3ec6ac31b385cdf53be53450\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_bdeaa46136dabcbb\" target=\"_blank\" rel=\"noopener\">ae4601a19d28332a3ec6ac31b385cdf53be53450<\/a><\/p>\n<p>Trojan downloaders:<br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/9803604ec45f31f9ef75bcca1e1310d8ac1fc3a6\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_d1a6cfa214e86ec2\" target=\"_blank\" rel=\"noopener\">9803604ec45f31f9ef75bcca1e1310d8ac1fc3a6<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/edce72f59e4c1d136cd1946af70d334c19df858d\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_a79e0eeb72b3294d\" target=\"_blank\" rel=\"noopener\">edce72f59e4c1d136cd1946af70d334c19df858d<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/02819d200d1424882af81cb504b3e8614b32397a\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_b2dc6d34277c4187\" target=\"_blank\" rel=\"noopener\">02819d200d1424882af81cb504b3e8614b32397a<\/a><\/p>\n<p><strong>Domains and IPs<\/strong><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/asper1.freeddns.org\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_5af5721c3d04ecca\" target=\"_blank\" rel=\"noopener\">asper1[.]freeddns[.]org<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/winst0.kozow.com\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_85d779ab300d6798\" target=\"_blank\" rel=\"noopener\">Winst0[.]kozow[.]com<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/country1.ignorelist.com\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_9bce16a1fd92bf6e\" target=\"_blank\" rel=\"noopener\">Country1[.]ignorelist[.]com<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/186.158.223.35\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_1eef8b841aa40aed\" target=\"_blank\" rel=\"noopener\">186[.]158.223.35<\/a><\/p>\n<p><strong>GitHub repositories used in the campaign<\/strong><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/https%3A%2F%2Fgithub.com%2Fgmz159%2Fu\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_37a0b5b00eb4552b\" target=\"_blank\" rel=\"noopener\">hxxps:\/\/github[.]com\/gmz159\/u<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/https%3A%2F%2Fgithub.com%2Fdnyp%2Ffiles\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_f91a511412333a54\" target=\"_blank\" rel=\"noopener\">hxxps:\/\/github[.]com\/DnyP\/files<\/a><br \/>\n<a href=\"https:\/\/opentip.kaspersky.com\/https%3A%2F%2Fgithub.com%2Fmgzv%2Fp\/?utm_source=sl&amp;utm_medium=sl&amp;utm_campaign=sl&amp;icid=gl_sl_opentip-lnk_sm-team_72477af80b581e26\" target=\"_blank\" rel=\"noopener\">hxxps:\/\/github[.]com\/mgzv\/p<\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>In April 2026, we discovered a new malware campaign targeting players of \u201chentai\u201d games. Once launched, the infected games install a previously unknown malicious implant on the user\u2019s machine. After a few days, the implant downloads and executes a Trojan, resulting in full system compromise and broad remote control capabilities for the attackers. We dubbed [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-container-style":"default","site-container-layout":"default","site-sidebar-layout":"default","disable-article-header":"default","disable-site-header":"default","disable-site-footer":"default","disable-content-area-spacing":"default","footnotes":""},"categories":[1241,90,1240,248,99,232,233,587,236,257],"tags":[91],"class_list":["post-3471","post","type-post","status-publish","format-standard","hentry","category-argamal","category-cybersecurity","category-gaming-malware","category-great-research","category-malware","category-malware-descriptions","category-malware-technologies","category-rat","category-trojan","category-windows-malware","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.7 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Argamal: Malware hidden in hentai games - Imperative Business Ventures Limited<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Argamal: Malware hidden in hentai games - Imperative Business Ventures Limited\" \/>\n<meta property=\"og:description\" content=\"In April 2026, we discovered a new malware campaign targeting players of \u201chentai\u201d games. Once launched, the infected games install a previously unknown malicious implant on the user\u2019s machine. After a few days, the implant downloads and executes a Trojan, resulting in full system compromise and broad remote control capabilities for the attackers. We dubbed [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/\" \/>\n<meta property=\"og:site_name\" content=\"Imperative Business Ventures Limited\" \/>\n<meta property=\"article:published_time\" content=\"2026-06-03T10:03:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"headline\":\"Argamal: Malware hidden in hentai games\",\"datePublished\":\"2026-06-03T10:03:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/\"},\"wordCount\":2185,\"image\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Argamal\",\"Cybersecurity\",\"Gaming malware\",\"GReAT research\",\"Malware\",\"Malware descriptions\",\"Malware Technologies\",\"RAT\",\"Trojan\",\"Windows malware\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/\",\"url\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/\",\"name\":\"Argamal: Malware hidden in hentai games - Imperative Business Ventures Limited\",\"isPartOf\":{\"@id\":\"https:\/\/blog.ibvl.in\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg\",\"datePublished\":\"2026-06-03T10:03:58+00:00\",\"author\":{\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\"},\"breadcrumb\":{\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#primaryimage\",\"url\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg\",\"contentUrl\":\"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/blog.ibvl.in\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Argamal: Malware hidden in hentai games\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/blog.ibvl.in\/#website\",\"url\":\"https:\/\/blog.ibvl.in\/\",\"name\":\"Imperative Business Ventures Limited\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/blog.ibvl.in\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/blog.ibvl.in\"],\"url\":\"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Argamal: Malware hidden in hentai games - Imperative Business Ventures Limited","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/","og_locale":"en_US","og_type":"article","og_title":"Argamal: Malware hidden in hentai games - Imperative Business Ventures Limited","og_description":"In April 2026, we discovered a new malware campaign targeting players of \u201chentai\u201d games. Once launched, the infected games install a previously unknown malicious implant on the user\u2019s machine. After a few days, the implant downloads and executes a Trojan, resulting in full system compromise and broad remote control capabilities for the attackers. We dubbed [&hellip;]","og_url":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/","og_site_name":"Imperative Business Ventures Limited","article_published_time":"2026-06-03T10:03:58+00:00","og_image":[{"url":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg","type":"","width":"","height":""}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#article","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/"},"author":{"name":"admin","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"headline":"Argamal: Malware hidden in hentai games","datePublished":"2026-06-03T10:03:58+00:00","mainEntityOfPage":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/"},"wordCount":2185,"image":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#primaryimage"},"thumbnailUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg","keywords":["Cybersecurity"],"articleSection":["Argamal","Cybersecurity","Gaming malware","GReAT research","Malware","Malware descriptions","Malware Technologies","RAT","Trojan","Windows malware"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/","url":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/","name":"Argamal: Malware hidden in hentai games - Imperative Business Ventures Limited","isPartOf":{"@id":"https:\/\/blog.ibvl.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#primaryimage"},"image":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#primaryimage"},"thumbnailUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg","datePublished":"2026-06-03T10:03:58+00:00","author":{"@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02"},"breadcrumb":{"@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#primaryimage","url":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg","contentUrl":"https:\/\/media.kasperskycontenthub.com\/wp-content\/uploads\/sites\/43\/2026\/06\/03065220\/SL-Argamal-hentai-game-trojan-featured-990x400.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/blog.ibvl.in\/index.php\/2026\/06\/03\/argamal-malware-hidden-in-hentai-games\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/blog.ibvl.in\/"},{"@type":"ListItem","position":2,"name":"Argamal: Malware hidden in hentai games"}]},{"@type":"WebSite","@id":"https:\/\/blog.ibvl.in\/#website","url":"https:\/\/blog.ibvl.in\/","name":"Imperative Business Ventures Limited","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blog.ibvl.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/55b87b72a56b1bbe9295fe5ef7a20b02","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blog.ibvl.in\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4d20b2cd313e4417a599678e950e6fb7d4dfa178a72f2b769335a08aaa615aa9?s=96&d=mm&r=g","caption":"admin"},"sameAs":["https:\/\/blog.ibvl.in"],"url":"https:\/\/blog.ibvl.in\/index.php\/author\/admin_hcbs9yw6\/"}]}},"_links":{"self":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/3471","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/comments?post=3471"}],"version-history":[{"count":0,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/posts\/3471\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/media?parent=3471"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/categories?post=3471"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.ibvl.in\/index.php\/wp-json\/wp\/v2\/tags?post=3471"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}