Fake Leonardo DiCaprio Movie Torrent Drops Agent Tesla Through Layered PowerShell Chain
ID: e23f6cd1-0953-570e-a88b-3f11e19e5ee6
STIX ID: report--e23f6cd1-0953-570e-a88b-3f11e19e5ee6
Feed Name: Bitdefender Labs
Threat Score
**Malicious torrent campaign delivering Agent Tesla:** Bitdefender investigated a fake movie torrent that used a shortcut (CD.lnk) and subtitle-embedded PowerShell to unpack and decrypt staged payloads from disguised files (fake .m2ts and JPG archives), create a hidden scheduled task for persistence, and ultimately execute the Agent Tesla RAT entirely in memory, enabling credential and data theft while evading detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
