The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

2026-09-20T08:51:46Z•e89b04c659ddf5ade1c81b6acac47269913e01aad8ae5fa0b5ed8b4acfb248d8
AI-framework-securityAPTActive DirectoryAndroid-malwareGhostContainerICSMQTTMatrixMirage KittenNightEagleNodeRabbitPollCatRDPSolanaToy GhoulsValleyRATblockchain-C2exploitsindustrial-control-systemsinitial-accessmalwareproxy-botnet-widget?threat-intelligencetorrent-distributionvulnerabilities

What happened

Kaspersky Securelist RSS collection covering September–August 2026 threat intelligence, including malware campaigns, APT activity, backdoors, rootkits, industrial control system threats, Android proxy botnets, ransomware, and vulnerability trends. Notable activity includes MovieReaper spreading through compromised movie torrents with Solana-based C2 concealment; NightEagle targeting Russian organizations through GhostContainer, GitHub-hosted tools, Active Directory and RDP exploitation; Toy Ghouls backdoors using MQTT and Matrix/Element for command and control; Mirage Kitten malware targeting-

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
e89b04c659ddf5ade1c81b6acac47269913e01aad8ae5fa0b5ed8b4acfb248d8
Enrichment time
2026-09-20T08:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.