The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
2026-09-18T08:51:46Z•f35879678f57401f2c56e0051794c7f1f5eadab1821edf39509e2f901f134e1d
APTActive-DirectoryAndroidFinTechGitHubMQTTMatrixRDPTelegramWindows-rootkitaviationblockchain-C2cyber-espionageindustrial-control-systemsmalwareransomwarethreat-intelligencetorrent-distributionvulnerability-research
What happened
Kaspersky Securelist RSS feed highlighting recent threat research from August–September 2026, including MovieReaper torrent-delivered malware using Solana for C2 concealment, NightEagle exploitation of Active Directory and RDP, Toy Ghouls backdoors using MQTT and Matrix/Element, Mirage Kitten malware targeting aviation and FinTech, ValleyRAT distribution through fake adware, industrial-control threats, AI-framework vulnerabilities, Android proxy-botnet malware, HoneyMyte’s kernel-level rootkit, and Armored Likho Telegram-focused espionage tooling.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- f35879678f57401f2c56e0051794c7f1f5eadab1821edf39509e2f901f134e1d
- Enrichment time
- 2026-09-18T08:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.