The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Entertainment/Movie Production
Breach intelligence, attack campaigns, and threat reports targeting the Entertainment/Movie Production sector.
Explore Other Sectors
Entertainment/Movie Production Threat Reports
Entertainment Turned Weapon: How Cybercriminals Hide Advanced Malware in Popular Film Torrents
In September 2026, Kaspersky's Global Research and Analysis Team uncovered a sophisticated multi-stage malware campaign targeting individuals and organizations through compromised torrent files disguised as popular films including The Odyssey. Active since mid-August 2026, the attack affected hundreds of victims across Russia, Turkey, Japan, Kenya, Uganda, Colombia, and several European countries. The malware employs advanced evasion techniques including sandbox detection, UAC bypass, and uses the Solana blockchain for command-and-control infrastructure resilience, ultimately providing attackers with persistent remote access to compromised systems. This incident highlights the evolving sophistication of malware distribution campaigns that exploit legitimate entertainment content as attack vectors. The combination of social engineering through popular media, advanced technical evasion capabilities, and blockchain-based infrastructure represents a concerning trend in cybercrime operations that traditional security measures may struggle to detect and mitigate effectively.
2 days ago
Kill Chain
ChainScript RAT Leverages Polygon Blockchain to Evade Traditional C2 Takedowns
In September 2026, threat actors launched a sophisticated campaign using ClickFix lures to deploy ChainScript, a previously undocumented remote access trojan (RAT). The malware masquerades as legitimate software including Spotify, Zoom Workplace, and Microsoft Teams, using malicious Windows installers delivered through deceptive prompts. ChainScript employs an innovative EtherHiding-style command-and-control discovery mechanism leveraging Polygon blockchain smart contracts to dynamically locate active WebSocket infrastructure, making traditional takedown efforts significantly more challenging. The RAT provides extensive remote access capabilities including interactive command execution, file operations, screenshot capture, cryptocurrency wallet enumeration, and payload deployment across compromised systems. This incident highlights the growing sophistication of malware infrastructure design, particularly the adoption of decentralized blockchain-based C2 discovery methods that enable threat actors to maintain persistent access while evading conventional detection and disruption techniques.
3 days ago
Kill Chain
Scattered Spider Core Member Pleads Guilty to Multi-Million Dollar Cryptocurrency Theft Spree
Ahmed Hossam Eldin Elbadawy, a 24-year-old Texas resident and core member of the Scattered Spider cybercrime group, pleaded guilty to wire fraud conspiracy and aggravated identity theft charges in December 2023. Operating from 2021 to 2023, Elbadawy and his co-conspirators used social engineering tactics to compromise credentials at major companies across entertainment, telecom, technology, and cryptocurrency sectors. The group targeted high net worth individuals with virtual currency accounts, successfully stealing over $8.6 million in cryptocurrency, including individual thefts of $6.35 million, $571,000, and $1.7 million. Prosecutors are seeking forfeiture of over $17.6 million in Bitcoin and Ethereum, plus luxury assets including vehicles, watches, and designer goods. This case highlights the continued evolution of financially motivated cybercrime groups like Scattered Spider, which has grown to thousands of members despite law enforcement actions against early leaders. The group's sophisticated social engineering techniques and focus on cryptocurrency theft represent a persistent threat to organizations holding digital assets.
5 days ago
Kill Chain
MovieReaper Campaign Exploits Torrent Supply Chain with Blockchain-Resilient C2
The MovieReaper campaign, active since October 2025, represents a sophisticated multi-stage malware operation targeting users across multiple countries through compromised torrent trackers. Threat actors compromised the itorrents.org repository, causing legitimate torrent sites to inadvertently distribute malicious files disguised as popular movies like 'The Odyssey (2026).' The attack chain employs advanced evasion techniques, uses Solana blockchain for C2 resilience, and deploys a modular framework capable of comprehensive file system access and data exfiltration. Victims span individuals and organizations across Europe, Asia, and Africa, including sectors like government, IT, retail, and transportation. This incident highlights the evolving sophistication of supply chain attacks targeting content distribution platforms and the increasing use of blockchain infrastructure to create resilient command and control networks that resist traditional takedown efforts.
1 week ago
Kill Chain
How HBO Max's Hijacked Reddit Account Became a Malware Distribution Network
In September 2026, cybercriminals compromised HBO Max's verified Reddit account and launched 108 malicious advertisements over 48 hours, targeting both Windows and macOS users through ClickFix social engineering attacks. The campaign, linked to the broader PasteSwitch operation, tricked victims into executing malicious commands through legitimate system tools like PowerShell and Terminal, bypassing traditional security controls. The attacks distributed information stealers including MacSync and Amatera Stealer, cryptocurrency clippers, and fake wallet applications, demonstrating sophisticated multi-platform targeting capabilities. This incident represents a significant escalation in social media account takeover attacks, where threat actors exploit trusted brand verification to distribute malware at scale. The use of ClickFix techniques shows how attackers are evolving to bypass modern security tools by manipulating users into executing malicious code through legitimate operating system functions.
1 week ago
Kill Chain
How a Malicious Twitch Extension Stole 30,000 Users' OAuth Tokens
In September 2026, security researchers discovered that the 'Twitch Enhanced Viewer | JeetBot' browser extension, installed by over 30,000 users across Chrome and Firefox stores, was secretly harvesting users' OAuth authentication tokens. The extension, marketed as a legitimate Twitch enhancement tool for ad-blocking and quality improvements, redirected users' streaming requests through Russian-operated proxy servers while embedding authentication credentials in URL parameters, making them easily accessible in server logs. This supply-chain attack demonstrates the persistent risk of malicious browser extensions infiltrating official app stores despite security reviews. This incident highlights the growing trend of credential theft through seemingly legitimate browser extensions, coinciding with increased regulatory scrutiny of third-party software supply chains and the need for enhanced OAuth token security practices.
1 week ago
Kill Chain
JeetBot Extension Compromises 31,000 Twitch Users in Massive OAuth Token Theft
In September 2026, a malicious Twitch browser extension called 'Twitch Enhanced Viewer | JeetBot' was discovered exposing OAuth tokens from nearly 31,000 users across Chrome and Firefox platforms. The extension, developed by HISHIMIRO/jeetbot.cc and operated by Cyprus-based developer Aleksandr Popov, routed users' authenticated Twitch sessions through operator-controlled proxy servers while claiming to provide ad-free viewing and region-unlocked content. The OAuth tokens were transmitted in cleartext as URL query parameters, enabling unauthorized access to users' chat, private messages, and account settings. Interestingly, the token forwarding mechanism excluded a hardcoded list of ten Russian streamer channels with large followings. This incident highlights the growing threat of supply chain attacks targeting browser extensions and the critical importance of OAuth token security in modern web applications. As streaming platforms and social media continue to expand globally, malicious actors are increasingly exploiting trusted software distribution channels to harvest user credentials at scale.
1 week ago
Kill Chain
First Take It Down Act Conviction: James Strahler's AI Sextortion Campaign Exposes Deepfake Threat Landscape
Between December 2024 and June 2025, Ohio resident James Strahler II conducted an extensive AI-powered sextortion campaign targeting multiple women through cyberstalking, harassment, and the creation of non-consensual deepfake pornography. Using over 100 AI web-based models across 24 platforms, Strahler generated more than 700 sexually explicit images and videos of his victims, which he distributed to their workplaces and posted on child exploitation websites. His tactics included threatening victims and their families with public humiliation unless they provided additional explicit content, making rape threats referencing home addresses, and demanding compliance from victims' mothers. The case resulted in a 15-year federal prison sentence and marked the first conviction under the newly enacted Take It Down Act of 2025. This incident highlights the emerging threat landscape where readily accessible AI tools are being weaponized for sophisticated harassment campaigns, demonstrating how threat actors are adapting generative AI capabilities for malicious purposes at an unprecedented scale and sophistication level.
2 weeks ago
Kill Chain
Mass Plex Server Exposure: 36,000 Vulnerable Instances Highlight Critical Patch Management Gaps
In September 2026, over 36,000 Plex Media Server instances remained exposed online and unpatched against critical security vulnerabilities affecting version 1.43.2 and earlier. Plex urgently warned users to upgrade to version 1.43.3, released in May 2026, to address multiple security flaws that lack CVE identifiers for easy tracking. The company took the unusual step of emailing customers directly about the severity of these vulnerabilities. Shadowserver's scanning revealed the massive scale of exposure, with tens of thousands of servers remaining vulnerable to potential exploitation as attackers could reverse-engineer the patches to develop exploits. This incident highlights the persistent challenge of vulnerability management in internet-exposed services, particularly as organizations increasingly rely on media streaming and file sharing platforms that may lack enterprise-grade security controls and patch management processes.
2 weeks ago
Kill Chain
Critical Bluetooth Flaw Exposes Millions of Skullcandy Dime 3 Users to Device Hijacking
Skullcandy Dime 3 wireless earbuds contain a critical Bluetooth vulnerability (CVE-2025-20701) that allows attackers to hijack devices without user interaction. The flaw exists in the Airoha Bluetooth Audio SDK used by these popular earbuds, enabling nearby attackers to connect without pairing PINs or approval requests. Once connected, attackers can intercept audio, access microphone feeds, and maintain persistent access through automatic reconnection. While Skullcandy released firmware version 1.0.0.30 to address the issue, existing users with vulnerable firmware version 1.0.0.28 have no available update mechanism through the mobile app or other consumer-accessible methods. This incident highlights the growing threat landscape targeting IoT devices and consumer electronics, particularly as Bluetooth-based attacks become more sophisticated and accessible to threat actors seeking to exploit trusted device relationships for surveillance and data collection purposes.
2 weeks ago
Kill Chain
Inside CL-CRI-1171: The Massive Pay-Per-Install Network That Hid in Plain Sight
In September 2026, Unit 42 researchers uncovered CL-CRI-1171, a sophisticated pay-per-install (PPI) malware distribution network that operated undetected for over two years. The cybercrime group leveraged YouTube gaming channels with hundreds of thousands of followers and SEO poisoning techniques to distribute multiple malware families including Insomnia RAT, ARKTunnel, and Docro Hijacker. The operation used OfferLoader, a custom Inno Setup-based loader, to deploy over 10,000 distinct payload combinations across corporate networks, critical infrastructure, and government entities while evading detection through clever gating mechanisms and unremarkable appearance. This campaign highlights the growing threat of commodity infrastructure being weaponized for large-scale malware distribution, particularly as threat actors increasingly target younger demographics through gaming platforms and use legitimate-seeming tools to bypass security scrutiny.
2 weeks ago
Kill Chain
Critical Plex Security Update: Multiple Vulnerabilities Patched in September 2026
In September 2026, Plex urged users to immediately update their Media Server and Desktop applications following the discovery of multiple undisclosed security vulnerabilities. The streaming media service released patches in Plex Media Server version 1.43.3 and Plex Desktop 1.115.0, with CVE identifiers requested for the flaws. While technical details remain undisclosed, this follows a pattern of critical Plex vulnerabilities, including a high-severity authentication bypass flaw (CVE-2025-34158) patched in August 2025 that exposed server owner credentials to any authenticated user. This incident highlights the ongoing security challenges facing media streaming infrastructure, particularly as threat actors increasingly target home and small business servers. With over 360,000 Plex servers exposed to the internet and a history of exploitation including the 2022 LastPass breach chain, these vulnerabilities underscore the critical need for rapid patch deployment and network segmentation.
2 weeks ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports