The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

2026-09-20T20:51:45Z•b714dcdfc7802d2fb6d631cddc7ec76c69c99910b1c879469f46dbfda04f4dd6
AI securityAPTActive Directory exploitationAndroidFinTechGitHubJavaScriptMQTTMatrixNode.jsRDP exploitationSolanaTelegram theftadwareaviationbackdoorsblockchain C2campaignscyber espionageindustrial control systemskernel rootkitmalwareproxy botnettorrent distributionvulnerabilities

What happened

Kaspersky Securelist RSS entries report multiple 2026 campaigns, including MovieReaper malware distributed through compromised movie torrents with Solana-based C2 concealment; NightEagle intrusions using GhostContainer, GitHub-hosted tools, and Active Directory/RDP exploitation; Toy Ghouls backdoors using MQTT and Matrix for command and control; Mirage Kitten malware targeting aviation and FinTech in the Middle East and Africa; ValleyRAT disguised as adware; Android malware targeting DoFun vehicle head units to create an advertising proxy botnet; HoneyMyte CoolClient with a kernel-level rootkt

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
b714dcdfc7802d2fb6d631cddc7ec76c69c99910b1c879469f46dbfda04f4dd6
Enrichment time
2026-09-20T20:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.