The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
2026-09-19T08:51:45Z•982b9e304e1857a7d3fc74410797218936bb142db0f3885568c62dc47c221ceb
APTActive-DirectoryAndroidFinTechGitHubMQTTMatrix-ElementRDPTelegramaviationbackdoorblockchain-C2cyber-espionageindustrial-control-systemskernel-rootkitmalwareproxy-botnetransomwaretorrent-distributiontrojanvulnerability-exploitation
What happened
Kaspersky Securelist RSS entries describe multiple 2026 cyber-threat campaigns, including MovieReaper malware distributed through compromised movie torrents with Solana-based C2 concealment; NightEagle exploitation of Active Directory and RDP vulnerabilities; Toy Ghouls backdoors using HiveMQ MQTT and Matrix Element for command and control; Mirage Kitten malware targeting aviation and FinTech; ValleyRAT disguised as adware; Android proxy-botnet malware delivered through DoFun vehicle head-unit software; HoneyMyte CoolClient with a kernel-level rootkit; and Armored Likho tooling for Telegram17?
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 982b9e304e1857a7d3fc74410797218936bb142db0f3885568c62dc47c221ceb
- Enrichment time
- 2026-09-19T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.