{"id":15742,"date":"2026-06-15T00:03:20","date_gmt":"2026-06-15T00:03:20","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=15742"},"modified":"2026-06-15T00:03:20","modified_gmt":"2026-06-15T00:03:20","slug":"hackers-cover-new-argamal-malware-inside-working-hentai-video-games","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=15742","title":{"rendered":"Hackers Cover New Argamal Malware Inside Working Hentai Video games"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p class=\"wp-block-paragraph\">Cybersecurity agency Kaspersky has found a brand new marketing campaign delivering malware to individuals downloading grownup video video games. Detected in April 2026, Kaspersky\u2019s investigation means that this malware is known as Argamal, and it&#8217;s hidden inside hentai recreation installers. Argamal is a distant entry Trojan (<a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/tag\/RAT\/\" data-type=\"post_tag\" data-id=\"27323\">RAT<\/a>) that permits hackers to remotely management an individual\u2019s pc.<\/p>\n<p class=\"wp-block-paragraph\">Researchers notice that Regular web scams normally provide you with a damaged file that won&#8217;t open. These contaminated downloads really embrace totally working video games constructed on frequent techniques like RenPy or RPG Maker. The sport runs precisely as you need it to, so that you by no means realise your machine is beneath somebody\u2019s management.<\/p>\n<h3 id=\"how-the-attack-works\" class=\"wp-block-heading\"><strong>How the Assault Works<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">These malicious recordsdata are distributed by way of completely different platforms comparable to grownup recreation websites, file-sharing platforms like PixelDrain, and torrent trackers comparable to AniRena. The sport archive, when downloaded, launches a rigged model of a typical library file known as FFmpeg DLL and one other file named <code>natives2_blob.bin<\/code> proper after the sport begins. <\/p>\n<p class=\"wp-block-paragraph\">This rigged library hundreds into the pc reminiscence with none warning screens popping up, and instantly runs a PowerShell script. To keep away from detection, the script first checks the system for monitoring instruments like <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/l0rdix-dark-web-malware-steals-data-mines-crypto-botnet\/\" data-type=\"post\" data-id=\"68031\">Sandboxie<\/a> or Procmon64.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers.png\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"225\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-1024x225.png\" alt=\"\" class=\"wp-image-146515\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-1024x225.png 1024w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-300x66.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-768x169.png 768w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-1536x338.png 1536w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-380x83.png 380w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-800x176.png 800w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-1160x255.png 1160w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\"\/><\/a><figcaption class=\"wp-element-caption\">Malicious recreation torrent in AniRena (Supply: Kaspersky Securelist)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">If the pc appears secure, the <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/atomic-arch-hijacks-linux-aur-packages-malware\/\">malware<\/a> waits. Three days later, a scheduled job opens and makes use of a instrument known as bitsadmin.exe to obtain an encrypted file (zaesdl.dat) from GitHub, and decrypts it utilizing AES-CBC encryption to create the principle Trojan module.<\/p>\n<p class=\"wp-block-paragraph\">To make sure persistence on the machine, the malware makes use of COM hijacking. It alters the registry entries for an actual Home windows function known as the Home windows Coloration System Calibration Loader. This function runs each time a consumer logs into their PC, which means the malware robotically begins up throughout each new consumer session.<\/p>\n<h3 id=\"what-hackers-can-do\" class=\"wp-block-heading\"><strong>What Hackers Can Do<\/strong><\/h3>\n<p class=\"wp-block-paragraph\">Argamal malware instantly sends UDP heartbeats (updates) to attackers\u2019 servers as soon as energetic on the machine. These servers are hosted on domains comparable to <code>asper1.freeddns.org<\/code> and <code>Winst0.kozow.com<\/code>. <\/p>\n<p class=\"wp-block-paragraph\">This permits the attackers full management over the system. They&#8217;ll now carry out malicious actions of all types, starting from stealing recordsdata, studying personal chats, and gathering monetary information to taking screenshots, swapping crypto-wallet addresses, and streaming dwell movies.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-1-1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"711\" height=\"1000\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-1-1.png\" alt=\"\" class=\"wp-image-146517\" style=\"aspect-ratio:0.7110095383199225;width:634px;height:auto\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-1-1.png 711w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-1-1-213x300.png 213w, https:\/\/hackread.com\/wp-content\/uploads\/2026\/06\/Argamal-RAT-Hides-Inside-Hentai-Game-Installers-to-Hijack-Computers-1-1-380x534.png 380w\" sizes=\"auto, (max-width: 711px) 100vw, 711px\"\/><\/a><figcaption class=\"wp-element-caption\">Sport archive contents (Supply: Kaspersky Securelist)<\/figcaption><\/figure>\n<\/div>\n<p class=\"wp-block-paragraph\">Kaspersky has detected a whole lot of customers contaminated up to now, principally in Russia, Brazil, Germany, and Vietnam. Code evaluation means that the attackers converse Spanish. An important discovering is that the malware purposefully avoids concentrating on customers in <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"noopener\" href=\"https:\/\/hackread.com\/tag\/China\/\" data-type=\"post_tag\" data-id=\"309\">China<\/a>. However, all customers of Hentai video games should keep away from unverified grownup websites and use real-time safety software program.<\/p>\n<p class=\"wp-block-paragraph\">(Photograph by Urim Pormeia on <a rel=\"nofollow\" target=\"_blank\" target=\"_blank\" rel=\"nofollow noopener\" href=\"https:\/\/unsplash.com\/photos\/a-person-standing-in-front-of-a-large-poster-p1uZ85QzNts?utm_source=unsplash&amp;utm_medium=referral&amp;utm_content=creditCopyText\">Unsplash<\/a>)<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="RxsfRWr3L15QuPGKEt8B"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity agency Kaspersky has found a brand new marketing campaign delivering malware to individuals downloading grownup video video games. Detected in April 2026, Kaspersky\u2019s investigation means that this malware is known as Argamal, and it&#8217;s hidden inside hentai recreation installers. Argamal is a distant entry Trojan (RAT) that permits hackers to remotely management an individual\u2019s [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":15744,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[9434,354,554,9435,2905,216,3146],"class_list":["post-15742","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-argamal","tag-games","tag-hackers","tag-hentai","tag-hide","tag-malware","tag-working"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15742","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15742"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15742\/revisions"}],"predecessor-version":[{"id":15743,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/15742\/revisions\/15743"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/15744"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15742"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15742"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15742"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-15 02:40:59 UTC -->