Kaspersky reported a malware campaign that trojanized adult “hentai” games to install a previously unknown remote access trojan, Argamal, on Windows systems. The attackers distributed modified game files through dedicated adult-game websites, PixelDrain links, torrent trackers including AniRena, and fake cheat posts on gaming forums. The infection chain relied on DLL side-loading and PowerShell-based download stages, then established persistence by COM hijacking the Windows Color System Calibration Loader task before deploying the full RAT.
Argamal was described as a full-featured backdoor that used encrypted payloads hosted on GitHub, anti-analysis checks, and both UDP and TCP channels for command-and-control and payload updates. Kaspersky said the campaign had already infected hundreds of victims, with most cases observed in Russia, Brazil, Germany, and Vietnam, and noted that associated C2 domains largely resolved to 186.158.223.35. The company assessed with medium confidence that the developer behind the downloader chain is Spanish-speaking.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Kaspersky assessed with moderate confidence that the developers behind Argamal are Spanish-speaking, citing Spanish-language code comments, variable names, and website code. The report also noted the malware excluded Chinese-language systems from normal C2 routing.
Kaspersky described a malware campaign it discovered in April 2026 in which adult “hentai” games were trojanized to deliver a previously unknown malware family named Argamal. The campaign used modified game files, DLL side-loading, PowerShell download stages, COM hijacking for persistence, and GitHub-hosted encrypted payloads, with hundreds of victims reported across multiple countries.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourcesecurityonline.info
Open sourcexakep.ru
Open sourcemalware.news
Open sourcesecurelist.ru
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.