logo

Fake Leonardo DiCaprio Movie Torrent Drops Agent Tesla Through Layered PowerShell Chain

ID: e23f6cd1-0953-570e-a88b-3f11e19e5ee6

STIX ID: report--e23f6cd1-0953-570e-a88b-3f11e19e5ee6

Feed Name: Bitdefender Labs

Threat Score
72/100

Date Published: 2025-12-10

Date Updated: 2026-04-27

Author: Raul Vasile BUCUR

...
...

**Malicious torrent campaign delivering Agent Tesla:** Bitdefender investigated a fake movie torrent that used a shortcut (CD.lnk) and subtitle-embedded PowerShell to unpack and decrypt staged payloads from disguised files (fake .m2ts and JPG archives), create a hidden scheduled task for persistence, and ultimately execute the Agent Tesla RAT entirely in memory, enabling credential and data theft while evading detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.