Argamal is a remote access trojan (RAT) identified by Kaspersky in April 2026. It targets individuals downloading adult video games, especially hentai games, and is distributed through trojanized game installers and archives on adult game websites, PixelDrain, torrent trackers including AniRena, and gaming forums where some samples were disguised as cheats. The malicious archives contain legitimate working games, helping the malware avoid suspicion.
The infection chain uses modified game components, including a patched ffmpeg.dll and a file named natives2_blob.bin, to execute Base64-encoded PowerShell. The malware performs anti-analysis checks for tools such as Sandboxie and Procmon64, delays the next stage for three days, then uses bitsadmin.exe to download an encrypted payload such as zaesdl.dat from GitHub and decrypts it with AES-CBC. Argamal establishes persistence through COM hijacking by modifying registry entries associated with the Windows Color System Calibration Loader scheduled task so the payload runs at user logon.
Once active, Argamal communicates with attacker-controlled infrastructure including asper1.freeddns.org and Winst0.kozow.com, both observed resolving to 186.158.223.35, and sends UDP heartbeat traffic containing host details such as security products, architecture, IP address, and username. In extended RAT mode it also uses TCP communications. Reported capabilities include remote command execution, file theft and exfiltration, file deletion, screenshot capture, private chat access, financial data collection, archive creation, cursor control, simulated key presses, reboot and shutdown, downloading additional payloads, cryptocurrency wallet address replacement, and live video streaming.
Kaspersky reported hundreds of infections, primarily affecting private individuals in Russia, Brazil, Germany, and Vietnam. The malware includes logic to avoid normal targeting of systems with the zh-CN locale. Based on Spanish-language comments, variable names, and related artifacts, Kaspersky assessed with medium to moderate confidence that the developer or operators are Spanish-speaking.
Known indicators and artifacts directly mentioned in reporting include ffmpeg.dll SHA1 42add9475e67a1ccc6a6af94b5475d3defc01b85, natives2_blob.bin SHA1 edce72f59e4c1d136cd1946af70d334c19df858d, C2 domains asper1.freeddns.org, Winst0.kozow.com, and country1.ignorelist.com, IP address 186.158.223.35, UDP ports 57441 and 63559, TCP port 3747, and persistence via HKCU\SOFTWARE\Classes\CLSID{B210D694-C8DF-490D-9576-9E20CDBC20BD} tied to the Windows Color System Calibration Loader task.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Атаки начинаются с архивов, содержащих зараженную игру. После запуска на компьютер жертвы устанавливается скрытый вредоносный модуль.
These malicious files are distributed via different platforms such as adult game sites, file-sharing platforms like PixelDrain, and torrent trackers such as AniRena. These infected downloads actually include fully working games built on common systems like RenPy or RPG Maker.
Both the dedicated websites and torrents delivered an archive containing the infected game. This archive contained fully functional, legitimate game files, as well as a modified FFmpeg DLL... Since the game needs ffmpeg.dll to run properly, the library loads as soon as the user starts the game.
this remote access trojan (RAT) is hidden within installers of hentai games... The Argamal malware is distributed through adult game websites, file-sharing platforms, and torrent trackers. Infected installers contain fully functional games, making them appear legitimate.
If the computer seems safe, the malware waits. Three days later, a scheduled task opens and uses a tool called bitsadmin.exe to download an encrypted file (zaesdl.dat) from GitHub.
После этого операторы Argamal могут удаленно выполнять команды на зараженной машине...
Upon launching, the malware executes a PowerShell script that checks for security tools before establishing a connection to attacker-controlled servers.
0x53 Execute command from the response using ShellExecuteW 0x52 Run the file specified in the response using WinExec
Three days later, a scheduled task opens and uses a tool called bitsadmin.exe to download an encrypted file (zaesdl.dat) from GitHub.
Атаки начинаются с архивов, содержащих зараженную игру. После запуска на компьютер жертвы устанавливается скрытый вредоносный модуль.
If the computer seems safe, the malware waits. Three days later, a scheduled task opens and uses a tool called bitsadmin.exe to download an encrypted file (zaesdl.dat) from GitHub.
It alters the registry entries for a real Windows feature called the Windows Color System Calibration Loader.
The natives2_blob.bin file is a DLL that executes a Base64-encoded PowerShell script ... Early payload versions decrypted themselves ... The samples we found had string encryption ... TCP communications are encrypted using a simple substitution cipher.
Three days later, a scheduled task opens and uses a tool called bitsadmin.exe to download an encrypted file (zaesdl.dat) from GitHub.
To avoid detection, the script first checks the system for monitoring tools like Sandboxie or Procmon64.
After a three-day delay, it downloads and decrypts its main module using AES-CBC encryption.
These heartbeats contain information about ... username ... USER : sends username
проверяет наличие защитных продуктов... анализируя вывод команды tasklist ... команда 0x50: собрать информацию о зараженной системе (например, список процессов)
Подробный технический анализ малвари показал, что Argamal может ... собирать информацию о защитном ПО на устройстве...
LFILES <путь к папке> : перечисляет и передает пути ко всем файлам в каталоге.
To avoid detection, the script first checks the system for monitoring tools like Sandboxie or Procmon64.
Upon launching, the malware executes a PowerShell script that checks for security tools before establishing a connection to attacker-controlled servers.
25 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remote access trojan hidden in installers for adult video games. It executes a PowerShell script, checks for security tools, connects to attacker-controlled servers, delays payload retrieval for three days, decrypts its main module with AES-CBC, establishes persistence via Windows Color System Calibration Loader hijacking, and can steal files, access chats, gather financial data, take screenshots, alter crypto-wallet addresses, and stream live video.
A remote access Trojan delivered via trojanized adult game installers. It executes through a rigged FFmpeg DLL and PowerShell, delays payload retrieval by three days, downloads an encrypted module from GitHub, uses AES-CBC decryption, establishes persistence via COM hijacking of the Windows Color System Calibration Loader, sends UDP heartbeats to attacker servers, and enables full remote control including file theft, chat access, financial data collection, screenshots, crypto-wallet address swapping, and live video streaming.
Argamal is a trojanized malware family distributed via adult video game archives on torrent sites. It uses a patched ffmpeg.dll for sideloaded execution, runs Base64-encoded PowerShell for environment checks and sandbox evasion, downloads an encrypted final payload from GitHub via bitsadmin.exe, establishes persistence through COM hijacking using an InprocServer32 registry entry tied to the WindowsColorSystem Calibration Loader scheduled task, and communicates with a C2 server over UDP to receive commands for actions such as file deletion, screenshots, and folder compression.
Previously unknown remote access trojan distributed via trojanized adult games, torrent trackers, and gaming forums. After infection it provides attackers near-complete control of the system, including remote command execution, screenshots, cursor control, file archiving and exfiltration, reboot/shutdown, persistence, security software reconnaissance, and downloading additional modules from C2 servers. The campaign appears focused on data and account theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.