logo

Argamal Trojan Campaign Targets Adult Gamers with COM Hijacking

ID: 79f44f99-b3c2-5b6d-84d6-eb53c14a9185

STIX ID: report--79f44f99-b3c2-5b6d-84d6-eb53c14a9185

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Do Son

...
...

Argamal is a Trojan campaign that spreads via trojanized game archives on torrent sites, using a modified ffmpeg.dll to load a hidden payload (natives2_blob.bin) and execute a Base64-encoded PowerShell stage that performs sandbox/locale checks. The campaign downloads an encrypted final payload via bitsadmin from GitHub, establishes persistence by registering the payload as an InprocServer32 COM object under HKCU\SOFTWARE\Classes\CLSID{B210D694-C8DF-490D-9576-9E20CDBC20BD} (tied to the WindowsColorSystem Calibration Loader task), and communicates with C2 over UDP port 57441 to receive remote-control commands; telemetry reports hundreds of victims mainly in Russia, Brazil, Germany, and Vietnam.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.