The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
2026-09-21T08:51:46Z•7174339ca227e498556e8d24969a3e10de89c127bc4158f0d52bd5f9d1e6d6e8
APTActive-DirectoryAndroidC2-obfuscationGitHubMQTTMatrixRDPSolanaTelegram-theftWindows-rootkitaviationbackdoorcyber-espionagefinancial-sectorindustrial-control-systemskernel-mode-rootkitmalwareproxy-botnetransomwaretorrent-distributiontrojanvulnerability-exploitation
What happened
Kaspersky Securelist RSS entries describe multiple malware and APT campaigns reported in August–September 2026, including torrent-delivered MovieReaper trojans using Solana for C2 concealment; NightEagle activity against Russian organizations involving GhostContainer, GitHub-hosted tools, Active Directory and RDP exploitation; Toy Ghouls backdoors using MQTT and Matrix/Element C2; Mirage Kitten malware targeting aviation and financial organizations; ValleyRAT distributed as adware; Android proxy-botnet malware targeting vehicle head units; HoneyMyte CoolClient with a kernel-level rootkit; and8
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 7174339ca227e498556e8d24969a3e10de89c127bc4158f0d52bd5f9d1e6d6e8
- Enrichment time
- 2026-09-21T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.