The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
2026-09-20T08:51:46Z•e89b04c659ddf5ade1c81b6acac47269913e01aad8ae5fa0b5ed8b4acfb248d8
AI-framework-securityAPTActive DirectoryAndroid-malwareGhostContainerICSMQTTMatrixMirage KittenNightEagleNodeRabbitPollCatRDPSolanaToy GhoulsValleyRATblockchain-C2exploitsindustrial-control-systemsinitial-accessmalwareproxy-botnet-widget?threat-intelligencetorrent-distributionvulnerabilities
What happened
Kaspersky Securelist RSS collection covering September–August 2026 threat intelligence, including malware campaigns, APT activity, backdoors, rootkits, industrial control system threats, Android proxy botnets, ransomware, and vulnerability trends. Notable activity includes MovieReaper spreading through compromised movie torrents with Solana-based C2 concealment; NightEagle targeting Russian organizations through GhostContainer, GitHub-hosted tools, Active Directory and RDP exploitation; Toy Ghouls backdoors using MQTT and Matrix/Element for command and control; Mirage Kitten malware targeting-
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- e89b04c659ddf5ade1c81b6acac47269913e01aad8ae5fa0b5ed8b4acfb248d8
- Enrichment time
- 2026-09-20T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.