The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
2026-09-20T20:51:45Z•b714dcdfc7802d2fb6d631cddc7ec76c69c99910b1c879469f46dbfda04f4dd6
AI securityAPTActive Directory exploitationAndroidFinTechGitHubJavaScriptMQTTMatrixNode.jsRDP exploitationSolanaTelegram theftadwareaviationbackdoorsblockchain C2campaignscyber espionageindustrial control systemskernel rootkitmalwareproxy botnettorrent distributionvulnerabilities
What happened
Kaspersky Securelist RSS entries report multiple 2026 campaigns, including MovieReaper malware distributed through compromised movie torrents with Solana-based C2 concealment; NightEagle intrusions using GhostContainer, GitHub-hosted tools, and Active Directory/RDP exploitation; Toy Ghouls backdoors using MQTT and Matrix for command and control; Mirage Kitten malware targeting aviation and FinTech in the Middle East and Africa; ValleyRAT disguised as adware; Android malware targeting DoFun vehicle head units to create an advertising proxy botnet; HoneyMyte CoolClient with a kernel-level rootkt
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- b714dcdfc7802d2fb6d631cddc7ec76c69c99910b1c879469f46dbfda04f4dd6
- Enrichment time
- 2026-09-20T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.