In April 2026, Kaspersky researchers uncovered a new malware campaign targeting players of hentai games. The attackers distributed trojanized game installers that, once executed, silently deployed a previously undocumented malicious implant on the victim's system. After a dormancy period of several days, the implant downloaded and executed a full-featured Trojan, granting the threat actors broad remote control capabilities and resulting in complete system compromise. Kaspersky has dubbed this malware family
Argamal.
Persistence Mechanism: COM Hijacking
Kaspersky researchers identified that Argamal achieves persistence through
COM hijacking, specifically by manipulating the
InprocServer32 registry entry associated with the
Windows Color System Calibration Loader DLL. By replacing this entry with a reference to the malicious DLL, the malware ensures it is loaded automatically each time the user logs into the system. This technique abuses a legitimate Windows component registration mechanism, allowing the implant to run at startup while blending into normal system activity and evading cursory inspection.
Detection
Kaspersky solutions detect the components of this threat under the following verdicts:
| Verdict | Component |
|---|
Trojan.Win32.Termixia.* | Trojan component(s) |
Trojan.Win32.Agent.* | Generic agent/loader components |
HEUR:Trojan.Win32.Argamal.gen | Heuristic detection of the core implant |
HEUR:Trojan-Downloader.Win32.Argamal.gen | Heuristic detection of the downloader stage |
Kaspersky researchers analyze new Argamal RAT distributed via infected hentai games and allowing the attacker to control the target machine.
securelist.com