Game Downloads Became a Persistent Windows Foothold

A game archive can now become a login-triggered implant, not just a bad download. Argamal uses a Windows startup mechanism so the malicious code loads when the user signs in, which means closing the game does not end the compromise. Kaspersky found the campaign in infected hentai games distributed through screenshot sites, file-hosting links, and torrent trackers like AniRena. The samples have existed since at least 2024, and after a few days the implant fetches a second-stage Trojan that gives the attacker full remote control on Windows systems. That shifts the risk from a one-time trojan to durable endpoint compromise on consumer PCs. The same trust gap applies anywhere users pull games or mods from torrents and file-hosting links.

Part of the PlainSec briefing for 2026-06-03

Every edition of this story: Game Downloads Became a Persistent Windows Foothold

Sources