✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Entertainment/Movie Production
Breach intelligence, attack campaigns, and threat reports targeting the Entertainment/Movie Production sector.
Explore Other Sectors
Entertainment/Movie Production Threat Reports
Instagram 2026: Data Scraping Leak Exposes 17 Million Accounts
In January 2026, security researchers and several hacking forums circulated claims that data for over 17 million Instagram accounts was leaked online. The incident is believed to stem from large-scale data scraping leveraging a password reset email bug, combined potentially with prior years' API vulnerabilities. The leaked dataset included a variety of personal information such as usernames, phone numbers, email addresses, and physical addresses. No passwords were exposed, and Meta (Instagram's parent company) denies that a system breach or new API compromise occurred, noting existing issues were promptly addressed and account security remains uncompromised. This case underscores the ongoing threat of data scraping and API abuse, where publicly accessible or insufficiently protected endpoints are targeted by cybercriminals. With the proliferation of social engineering attacks using scraped personal data and the repeated emergence of similar incidents across major platforms, the need for robust API security and user vigilance has never been greater.
6 months ago
Kill Chain
The Kimwolf & Aisuru Botnets: How Android TV Devices Fueled a Global Proxyware Crisis
In late 2025, the Kimwolf and Aisuru botnets collectively compromised over two million Android TV streaming boxes by leveraging factory-installed or bundled proxy malware. Attackers, operating through channels like Discord and Telegram, conscripted these devices for DDoS attacks, ad fraud, and mass content scraping. Investigations revealed overlapping cybercriminal operators, shared infrastructure, and direct monetization via residential proxy services such as Plainproxies, Maskify, and ByteConnect. The illicit operations exploited minimal device security, used decentralized technologies like Ethereum Name Service (ENS) for resilient command-and-control, and took advantage of poorly regulated server resellers in the U.S. and Europe. The incident underscores a rapidly evolving threat landscape where IoT/OTT devices are prime targets for distributed, difficult-to-mitigate botnets fueled by proxyware and privacy-invasive apps. It highlights urgent needs for better supply-chain security, IoT device hardening, and more robust detection and segmentation strategies to counter stealthy lateral movement and monetization tactics now seen across botnet campaigns.
6 months ago
Kill Chain
VVS Stealer: Obfuscated Python Malware Compromises Discord Accounts in 2025
In April 2025, researchers discovered a new information stealer, VVS Stealer, distributed via obfuscated Python code targeting Discord users. The malware, sold on Telegram, leverages Pyarmor obfuscation techniques to evade detection and focuses on harvesting Discord credentials and authentication tokens. Attackers propagated the malware through malicious campaigns that trick users into executing compromised scripts, resulting in unauthorized access to their Discord accounts. The impact was the loss of sensitive credentials, potential identity theft, and exposure of personal communications, with widespread risk for Discord communities and possibly further compromise of cloud-connected services. This incident exemplifies the growing sophistication in malware targeting online communities, particularly through social engineering and advanced obfuscation. There is a notable trend of threat actors exploiting popular platforms and leveraging encryption or evasion techniques to bypass standard security controls — elevating the urgency for endpoint protection, behavioral monitoring, and defense-in-depth controls.
6 months ago
Kill Chain
Kimwolf Botnet: When Residential Proxies Turn Your LAN Into a Global Attack Platform
In late 2025, a rapidly growing botnet called Kimwolf infected over two million devices worldwide, primarily through compromised Android TV boxes and digital photo frames lacking basic security controls or authentication. Attackers abused vulnerabilities in residential proxy networks—particularly via IPIDEA—to tunnel through external firewalls, gaining direct access to devices inside private networks. Kimwolf malware leveraged DNS tricks and default-enabled Android Debug Bridge (ADB) to enable lateral movement, turning victim devices into nodes for ad fraud, account takeovers, content scraping, and high-volume DDoS attacks, demonstrating unprecedented attacker reach into home and small business LANs. Kimwolf's swift expansion and post-takedown resilience reveal a new class of threats exploiting insecure IoT and overlooked network entry points inside residential and SMB environments. The incident highlights emerging risks from mass-produced, inadequately secured consumer tech and proxy networks, urging organizations to reconsider internal network trust assumptions and prioritize visibility, segmentation, and policy-driven controls to stop lateral movement and botnet proliferation.
6 months ago
Kill Chain
Evasive Panda: APT Delivers MgBot via DNS Poisoning in Asia (2022–2024)
Between November 2022 and November 2024, the Evasive Panda APT group executed a sophisticated campaign targeting victims primarily in Türkiye, China, and India. Leveraging adversary-in-the-middle (AitM) techniques and DNS poisoning, the attackers delivered a unique MgBot malware implant through fake software updates and stealthy loaders. The operation employed hybrid encryption, memory injection in signed executables, and evaded traditional defenses to maintain long-term persistence. Multiple new and legacy C2 infrastructures enabled sustained access while attackers tailored payloads based on the victim’s OS. This incident showcases the ongoing evolution of nation-state threat actors, utilizing advanced evasion, supply chain impersonation, and DNS manipulation to bypass security controls. It reflects a broader surge in attacks exploiting trust in software supply chains and underlines the need for continuously adaptive security strategies as actor sophistication grows.
6 months ago
Kill Chain
Critical 2025 UEFI Flaw Enables Pre-Boot DMA Attacks on Leading Motherboards
In December 2025, researchers from Riot Games identified a critical UEFI firmware vulnerability impacting motherboards from ASUS, Gigabyte, MSI, and ASRock. The flaw, tracked as CVE-2025-11901, CVE-2025‑14302, CVE-2025-14303, and CVE-2025-14304, allows Direct Memory Access (DMA) attacks during the pre-boot phase by bypassing IOMMU protections. Threat actors with physical access can attach malicious PCIe devices to read or alter system memory before the operating system loads, making traditional endpoint protections ineffective. The vulnerability was confirmed by multiple security advisories and coordinated with hardware vendors for urgent firmware updates. This incident highlights the increasing sophistication of firmware-level attacks that can evade operating system and security tool visibility. As hardware supply chains diversify and attackers target pre-boot processes, organizations face heightened risks in both enterprise and consumer hardware ecosystems.
6 months ago
Kill Chain
Inside Kimwolf: How 1.8 Million Android TVs Became a DDoS Botnet Army
In December 2025, cybersecurity researchers discovered the Kimwolf botnet had hijacked over 1.8 million Android-based smart TVs, set-top boxes, and tablets globally. The attackers leveraged the NDK (Native Development Kit) to compile malware that turned these consumer devices into a massive botnet used primarily for launching large-scale distributed denial-of-service (DDoS) attacks. The infected endpoints were recruited silently and spread across both residential and enterprise networks, enabling the attackers to conduct coordinated, high-bandwidth attacks and evade conventional network defenses. Initial findings also suggest a link between Kimwolf and the previously observed AISURU botnet, indicating possible collaboration or shared tooling between threat actors. This incident highlights a disturbing trend: threat actors increasingly targeting loosely protected IoT and smart device ecosystems for botnet creation. The scale and performance of Kimwolf underscore the growing risk posed by unpatched consumer electronics, calling for urgent improvements in east-west traffic security, segmentation, and network visibility across hybrid environments.
6 months ago
Kill Chain
SoundCloud 2024 Breach Exposes Member Data and VPN Vulnerabilities
In June 2024, SoundCloud experienced a significant security breach where threat actors compromised their infrastructure, resulting in outages and disruption of VPN connectivity. The attackers exfiltrated a database containing users' email addresses and profile information, exposing sensitive member data. The attack led to service interruptions that impacted both staff operations and user access, highlighting vulnerabilities in SoundCloud’s VPN and internal data security protocols. Subsequent investigations revealed that unencrypted network traffic and insufficient segmentation allowed the attackers to move laterally and extract confidential data. This incident exemplifies the growing trend of targeting cloud-based media platforms using sophisticated techniques, including exploiting VPN weaknesses and lateral movement within corporate networks. With regulatory scrutiny increasing around customer data privacy and the persistent rise in credential-driven breaches, organizations face mounting pressure to strengthen east-west security and encrypted network controls.
6 months ago
Kill Chain
ShinyHunters Extort PornHub: 2024 Analytics Breach Exposes Premium Member Data
In June 2024, adult content platform PornHub became the target of a significant data breach when the ShinyHunters extortion group claimed to have stolen search and viewing history data linked to the site’s Premium members. Attackers reportedly exploited Mixpanel analytics integrations to exfiltrate sensitive user data, including logs of user activity, then threatened public release unless a ransom was paid. PornHub’s operations and brand reputation face heightened scrutiny, especially given the highly sensitive nature of the data involved, with many users fearing exposure and potential blackmail. This incident underscores the ongoing threats facing organizations that handle sensitive personal data, especially as extortion groups increasingly target user activity logs for leverage. Regulatory and reputational risks are amplified by attackers’ focus on analytics platforms, and similar tactics are expected to proliferate across other high-traffic digital properties in 2024.
6 months ago
Kill Chain
Fake Movie Torrent Delivers Agent Tesla Infostealer via Subtitles in 2024
In early June 2024, cybersecurity researchers discovered that a malicious torrent purporting to offer the Leonardo DiCaprio film 'One Battle After Another' was distributing infostealer malware through booby-trapped subtitle files. Unsuspecting users who downloaded the fake torrent were exposed to malicious PowerShell loaders, which delivered the Agent Tesla remote access trojan (RAT). This malware enabled attackers to steal sensitive credentials, exfiltrate data, and remotely monitor infected devices, highlighting how threat actors weaponize popular entertainment content to bypass user defenses and propagate infostealers. The incident underscores the evolving threat landscape in which cybercriminals exploit widely-used file formats and trusted brands to lure victims. Multimedia supply chains are increasingly being targeted through creative means—such as doctored subtitles—with infostealers and RATs surging in popularity. Organizations and individuals must heighten their vigilance, especially as compliance scrutiny and attack techniques grow more sophisticated.
6 months ago
Kill Chain
Spyware, Mirai, Docker Leaks & ValleyRAT: Anatomy of a 2025 Multi-Vector Breach
In December 2025, a sophisticated multivector cyberattack campaign exploited vulnerabilities across popular software, container platforms, and download channels. Hackers leveraged malicious browser extensions, tainted movie torrents, and compromised Docker images to disseminate a blend of Mirai botnet variants, ValleyRAT rootkits, and advanced spyware, evading traditional perimeter defenses. The attackers utilized encrypted communications and east-west movement to escalate privileges and exfiltrate sensitive organizational data. Impacts included operational outages, ransom demands, exposure of proprietary assets, and regulatory notification obligations for affected companies across multiple industries. This attack illustrates the intensifying convergence of commodity malware, supply chain threats, and network infiltration techniques. With ransomware, spyware, and rootkits increasingly delivered via trusted collaboration or cloud platforms, and as attackers exploit hybrid environments, organizations face urgent pressure to revisit segmentation, detection, and zero trust controls.
6 months ago
Kill Chain
React2Shell Exploitation Delivers Crypto Miners and Advanced Malware Across Multiple Sectors
In December 2025, a sophisticated multi-vector cyber campaign exploited a critical vulnerability (CVE-2025-55182) in React Server Components, enabling unauthenticated remote code execution across more than 50 organizations in industries including construction, entertainment, finance, and government. Attackers orchestrated automated scans to identify vulnerable Next.js deployments and delivered a suite of malware, notably the PeerBlight backdoor, CowTunnel reverse proxy, ZinFoq implant, and various cryptominers. The campaign leveraged both Linux and Windows endpoints, indicating indiscriminate targeting. Highly persistent payloads established robust command-and-control connections, enabled lateral movement, and facilitated data exfiltration while evading detection using masquerading and decentralized C2 mechanisms. This incident underscores the urgency of prompt patching for popular web frameworks and highlights the growing sophistication and prevalence of automated exploitation tools. Security teams face amplified risk as threat actors now combine opportunistic cryptomining with advanced post-exploitation techniques across geographic regions and sectors, outpacing conventional defenses and incident response speeds.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports