The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

2026-09-18T20:51:45Z•68c704f1d1be05d4b520e36072381c719a4cb7475b5d89e3fa59e147220b5b0c
APTActive-DirectoryAfricaAndroid-malwareGitHubMQTTMiddle-EastRDPRussiaSolanabackdoorcommand-and-controlcyber-espionageindustrial-control-systemsmalwarephishingransomwarerootkittorrent-distributiontrojan

What happened

Kaspersky Securelist RSS entries describe multiple 2026 cyberthreat campaigns, including MovieReaper malware distributed through compromised movie torrents with Solana-based command-and-control concealment; NightEagle activity against Russian organizations using GhostContainer, GitHub-hosted tools, and Active Directory/RDP exploitation; Toy Ghouls backdoors using HiveMQ MQTT and Element; Mirage Kitten malware targeting aviation and FinTech in the Middle East and Africa; ValleyRAT disguised as adware; Android proxy-botnet malware targeting vehicle head units; HoneyMyte CoolClient with a kernel/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
68c704f1d1be05d4b520e36072381c719a4cb7475b5d89e3fa59e147220b5b0c
Enrichment time
2026-09-18T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents · Baitaphish