✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Entertainment/Movie Production
Breach intelligence, attack campaigns, and threat reports targeting the Entertainment/Movie Production sector.
Explore Other Sectors
Entertainment/Movie Production Threat Reports
Viral TikTok Malware Campaign Bypasses Security via Social Engineering and Infostealer
In October 2024, cyber attackers launched a widespread malware campaign on TikTok, leveraging viral videos that promised free software activations—such as Photoshop—to lure unsuspecting users. Victims were instructed to execute malicious PowerShell scripts, leading to the silent download of infostealers like AuroStealer and additional payloads that achieved persistence and utilized advanced in-memory code execution techniques. The highly effective social engineering exploited TikTok’s reach, spreading through multiple videos and targeting users seeking pirated software, resulting in significant risks of credential theft and further compromise. This attack exemplifies the growing trend of financially motivated threat actors exploiting popular social platforms for initial access. The use of self-compiling malware and in-memory shellcode injection reflects advanced tactics that bypass traditional security controls, highlighting the urgent need for robust endpoint protection, increased security awareness, and stricter monitoring of social media for malicious content.
6 months ago
Kill Chain
How a Breached BPO Account Led to Discord’s Massive 2025 Zendesk Data Breach
In late September 2025, attackers compromised a support agent account at an outsourced BPO provider and gained unauthorized access to Discord’s Zendesk support platform for 58 hours. Exploiting privileged access, they exfiltrated up to 1.6 TB of data, including approximately 8.4 million support tickets affecting 5.5 million users, with sensitive information such as emails, Discord IDs, phone numbers, partial payment data, and around 70,000 government-ID photos. The threat group leveraged integrations between Zendesk and Discord’s internal systems, extracted additional user details via APIs, and attempted a multimillion-dollar ransom before threatening public data release. This incident highlights the growing risk from third-party supply chain attacks targeting cloud-based customer support platforms and BPO providers. The attacker's tactics—abusing helpdesk integrations and privilege escalation—reflect broader cybercrime trends, including identity-driven attacks, data extortion, and rising regulatory scrutiny.
6 months ago
Kill Chain
DraftKings 2025 Credential Stuffing Breach: Lessons in Password Security
In October 2025, DraftKings, a prominent sports betting company, disclosed that less than 30 customer accounts were compromised via credential stuffing attacks. Threat actors utilized previously stolen username and password combinations from breaches of unrelated services, leveraging automated tools to gain unauthorized access to DraftKings user accounts. While the attackers obtained personal data such as names, addresses, dates of birth, contact details, and the last four digits of payment cards, there was no evidence of access to sensitive government-issued IDs or full financial account numbers. DraftKings responded swiftly by notifying affected users, requiring password resets, and recommending the use of multifactor authentication to mitigate further risk. This incident highlights the persistent threat of credential stuffing—an attack vector that exploits widespread password reuse. With large troves of leaked credentials available and automated attack tools on the rise, organizations across industries face increasing regulatory pressure to implement layered authentication and robust account monitoring to defend against identity-driven threats.
6 months ago
Kill Chain
Unity Game Engine Vulnerability 2025: Millions Exposed to Supply Chain Attacks
In October 2025, a significant supply chain vulnerability (CVE-2025-59489) was discovered in the Unity game engine, impacting applications built since version 2017.1 and endangering millions of global end-users. The flaw, identified by security researcher RyotaK, enables attackers to achieve arbitrary code execution or information disclosure by exploiting unsafe file loading mechanisms in the Unity Runtime component. Affected games include widely popular titles like Hearthstone, Fallout Shelter, and Doom (2019). Valve and Microsoft responded quickly, recommending users uninstall vulnerable games and developers patch or rebuild applications, while Unity issued updates and fixes for supported engine versions. This incident underscores the growing risks of supply chain vulnerabilities in modern software ecosystems, particularly as game engines and third-party frameworks become foundational across industries. The rapid coordinated response highlights heightened industry attention to upstream code security, as adversaries increasingly target widely deployed runtime components for maximum impact.
6 months ago
Kill Chain
Klopatra: The Stealth Android Banking Trojan Draining European Accounts Overnight
In mid-2024, the Klopatra Android banking Trojan emerged as a major threat to mobile users in Italy and Spain. Disguised as the popular but illicit Mobdro streaming app, the malware leveraged social engineering tactics to trick users into granting dangerous Accessibility permissions. Once installed, Klopatra used advanced obfuscation, anti-analysis techniques, and commercial packers to avoid detection. Attackers remotely took control of compromised devices while users slept, using stolen credentials and simulated taps to access and empty bank accounts through a series of stealthy transfers—all while remaining undetected until victims discovered their losses in the morning. The Klopatra incident underscores a rising trend in real-time, remote-controlled mobile banking fraud, combining overlays, credential theft, and session manipulation. As attackers continue targeting mobile banking, organizations and end-users must adapt defenses to evolving TTPs and maintain vigilance toward app sideloading.
6 months ago
Kill Chain
Boyd Gaming 2023 Data Breach Exposes Employee Information
In October 2023, Boyd Gaming Corporation, a major US gambling and casino operator, disclosed a data breach after threat actors infiltrated its network, stole sensitive data, and caused disruptions to company operations. The attackers gained unauthorized access to internal systems and exfiltrated data belonging to employees and a limited number of other individuals. While Boyd Gaming acted promptly to contain the incident and launched a forensic investigation, the breach led to operational disruptions and the exposure of personal information. The company notified regulators and affected individuals and engaged law enforcement in response efforts. This incident is significant due to the continued targeting of the gaming and hospitality sector by ransomware groups and other cybercriminals seeking valuable data. It also highlights the challenges organizations face in defending against complex threat tactics, and underscores the importance of robust security measures and employee data protection amid rising regulatory scrutiny.
6 months ago
Kill Chain
Steam’s Platform Breached: BlockBlasters Game Used for Massive 2025 Crypto Theft
In September 2025, a verified Steam game, BlockBlasters, was discovered to have been weaponized to steal cryptocurrency from users, including a content creator raising money for cancer treatment. Initially benign, the game was compromised on August 30 with a cryptodrainer component that harvested Steam credentials, IP addresses, and ultimately drained victims’ digital wallets. Attackers targeted high-value accounts sourced from social media, using a mix of batch scripts, Python backdoors, and StealC payloads, leading to an estimated $150,000 in theft across hundreds of accounts. At least one streamer lost $32,000 in funds intended for lifesaving care. This incident exemplifies the growing threat of supply-chain and platform abuse, with attackers leveraging trusted app marketplaces to deliver infostealers. The BlockBlasters case underscores the urgent need for advanced egress security, anomaly detection, and zero trust controls, as attackers increasingly exploit digital trust and social media to orchestrate high-impact thefts.
6 months ago
Kill Chain
Q2 2025 Mobile Malware Surge: Mamont and Triada Lead Sophisticated Attacks
In Q2 2025, Kaspersky detected a substantial wave of mobile malware impacting Android and iOS, blocking 10.71 million attacks involving Trojans, adware, and unwanted applications. The campaign was notable for a surge in banking Trojans—primarily the Mamont family—pre-installed backdoors like Triada, and novel threats such as SparkKitty, which targets crypto wallet recovery codes via image theft. Attackers leveraged fake app stores, porn-viewing apps that secretly built DDoS botnets, and deceptive VPNs that intercepted OTP codes through notification hijacking. Regionalized attacks exploited localized malware families to increase efficacy and evade global threat visibility, raising risks for financial and privacy exposure worldwide. This incident highlights a persistent trend of increasingly sophisticated mobile threats focused on financial theft and data exfiltration. The continued evolution of malware TTPs, including use of pre-installed Trojans, modular SDK-based payloads, and cross-platform attack vectors, emphasizes the urgent need for advanced endpoint protection and vigilant detection routines in the mobile security domain.
6 months ago
Kill Chain
Scattered Spider SIM-Swapping & Wire Fraud: Anatomy of a 2022 Corporate Breach
In 2022, a cybercriminal cell known as Scattered Spider orchestrated a widespread campaign of SIM-swapping and sophisticated social engineering attacks against major US companies. Led in part by 20-year-old Noah Michael Urban (alias "King Bob"), the group tricked mobile provider and corporate employees into divulging credentials and approving phishing requests, allowing attackers to hijack authentication flows and gain deep access to internal systems, including Okta and VPN platforms. Over several months, their schemes compromised more than 130 organizations—including Twilio, LastPass, DoorDash, and others—resulting in the theft of corporate and customer data, and millions in cryptocurrency. The operational impact included large-scale operational disruption and significant financial losses for victims. Scattered Spider’s tactics showed a fusion of SIM-swapping, credential phishing, and insider targeting that has reshaped industry concerns over identity-driven breaches and lateral movement. The group’s use of persistent social engineering, paired with technical exploitation, highlights the urgent need for organizations to strengthen multi-factor authentication, enforce Zero Trust principles, and adopt modern anomaly detection for internal east-west traffic.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports