The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

2026-09-17T20:51:46Z•e2ceec55f67685b7034cd5a45d30b3a1ca82890e0760a24d7a0ab2ef4026c039
APTActive-DirectoryAfricaAndroidFinTechGitHubICSJavaScriptMQTTMatrixMiddle-EastNode.jsRDPSolanaTelegramaviationblockchain-C2cyber-espionageindustrial-control-systemskernel-modemalwareproxy-botnetransomwarerootkittorrents

What happened

Kaspersky Securelist feed reporting on multiple 2026 cyber threats, including MovieReaper malware distributed through compromised movie torrents with Solana-based C2 concealment; NightEagle and GhostContainer activity against Russian organizations exploiting Active Directory and RDP; Toy Ghouls backdoors using HiveMQ MQTT and Matrix Element for command and control; Mirage Kitten malware targeting aviation and FinTech in the Middle East and Africa; ValleyRAT disguised as adware; Android proxy-botnet malware for automotive head units; HoneyMyte CoolClient with a kernel-level rootkit; Armored Lik

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
e2ceec55f67685b7034cd5a45d30b3a1ca82890e0760a24d7a0ab2ef4026c039
Enrichment time
2026-09-17T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.