The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

2026-09-19T08:51:45Z•982b9e304e1857a7d3fc74410797218936bb142db0f3885568c62dc47c221ceb
APTActive-DirectoryAndroidFinTechGitHubMQTTMatrix-ElementRDPTelegramaviationbackdoorblockchain-C2cyber-espionageindustrial-control-systemskernel-rootkitmalwareproxy-botnetransomwaretorrent-distributiontrojanvulnerability-exploitation

What happened

Kaspersky Securelist RSS entries describe multiple 2026 cyber-threat campaigns, including MovieReaper malware distributed through compromised movie torrents with Solana-based C2 concealment; NightEagle exploitation of Active Directory and RDP vulnerabilities; Toy Ghouls backdoors using HiveMQ MQTT and Matrix Element for command and control; Mirage Kitten malware targeting aviation and FinTech; ValleyRAT disguised as adware; Android proxy-botnet malware delivered through DoFun vehicle head-unit software; HoneyMyte CoolClient with a kernel-level rootkit; and Armored Likho tooling for Telegram17?

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
982b9e304e1857a7d3fc74410797218936bb142db0f3885568c62dc47c221ceb
Enrichment time
2026-09-19T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents · Baitaphish