A new malware campaign dubbed Argamal is targeting players of adult-themed games by deploying a remote access trojan that grants attackers full control over compromised Windows computer systems.
Key Points
- The Argamal malware is distributed through trojanized game files hosted on file-sharing services like PixelDrain and various torrent trackers.
- Attackers use COM hijacking and scheduled tasks to maintain persistence, ensuring the malicious payload executes automatically upon every user login.
- Once active, the malware functions as a Remote Access Trojan (RAT), capable of capturing screenshots, executing shell commands, and stealing sensitive user data.
- Kaspersky researchers identified hundreds of infections across Russia, Brazil, Germany, and Vietnam, noting that the threat actor continues to update the malware's infrastructure.
- The malicious code includes checks to detect and evade over 40 different security solutions, including products from Kaspersky, Avast, and McAfee.