CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Malicious Torrent Distributes Agent Tesla via Subtitle Files

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A fake torrent for the movie 'One Battle After Another' contains malicious PowerShell loaders hidden in subtitle files. When executed, these loaders infect devices with the Agent Tesla RAT malware. The infection chain involves multiple stages, including extracting encrypted data blocks from the subtitle file and deploying additional PowerShell scripts. The malware ultimately steals credentials and captures screenshots. This campaign highlights the use of subtitles as a stealthy vector for malware delivery.

Timeline

  1. 12.12.2025 19:12 1 articles · 23h ago

    Malicious Torrent for 'One Battle After Another' Distributes Agent Tesla

    A fake torrent for the movie 'One Battle After Another' contains malicious PowerShell loaders hidden in subtitle files. When executed, these loaders infect devices with the Agent Tesla RAT malware. The infection chain involves multiple stages, including extracting encrypted data blocks from the subtitle file and deploying additional PowerShell scripts. The malware ultimately steals credentials and captures screenshots.

    Show sources

Information Snippets