Intel Node
Argamal: Malware hidden in hentai games
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
Kaspersky researchers analyze new Argamal RAT distributed via infected hentai games and allowing the attacker to control the target machine.
In April 2026, we discovered a new malware campaign targeting players of “hentai” games. Once launched, the infected games install a previously unknown malicious implant on the user’s machine. After a few days, the implant downloads and executes a Trojan, resulting in full system compromise and broad remote control capabilities for the attackers. We dubbed this malware family “Argamal”. The malware uses COM hijacking to persist on the victim’s machine, replacing the InprocServer32 entry for Windows Color System Calibration Loader DLL.
This task is triggered when the user logs in, effectively allowing the malware to run at startup. Kaspersky solutions detect this threat as Trojan. Win32. Termixia. * , Trojan. Win32. Agent. * , HEUR:Trojan. Win32. Argamal. gen and HEUR:Trojan-Downloader. Win32. Argamal. gen .