The breach isn’t the problem. The spread is. →The breach isn’t the problem. The spread is. →Measure in 5 min. Free AssessmentFree Assessment
Entertainment/Movie Production
Breach intelligence, attack campaigns, and threat reports targeting the Entertainment/Movie Production sector.
Explore Other Sectors
Entertainment/Movie Production Threat Reports
AI-Powered Android Malware Unleashes New Click-Fraud Wave via Xiaomi App Store
In January 2026, cybersecurity researchers at Dr.Web uncovered a sophisticated new Android malware family distributed via Xiaomi’s GetApps, popular third-party APK sites, and messaging platforms like Telegram and Discord. This malware leverages AI-driven image analysis using Google’s TensorFlow.js to identify and autonomously click on hidden browser ads within compromised apps, particularly games, simulating user behavior without obvious signs to victims. The malware is delivered through legitimate-looking apps, which update with malicious payloads post-installation. Impacts include increased battery consumption, higher data charges, and indirect monetization for attackers. This incident exemplifies the evolution of mobile ad fraud TTPs, as attackers increasingly deploy AI/ML for advanced automation and evasion. The trend signals rising risks to mobile advertising integrity and higher scrutiny for app stores’ vetting processes, especially on third-party and OEM-specific app markets.
8 months ago
Kill Chain
Researchers Hijack StealC Malware Operators: 2026's XSS-Driven Counterattack
In January 2026, cybersecurity researchers uncovered and exploited a cross-site scripting (XSS) vulnerability in the web administration panel of the infamous StealC infostealer malware. By leveraging this flaw, the researchers were able to hijack malware operator sessions, collect hardware and geographic fingerprints, observe live threat actor activities, and even seize control of the attackers' own administration panels. One notable instance involved tracking a StealC affiliate operating as 'YouTubeTA', who stole credentials via malicious YouTube links that resulted in over 5,000 compromised devices and the theft of nearly 390,000 passwords and 30 million cookies. The research highlights critical operational risks inherent in the malware-as-a-service (MaaS) model, particularly as platforms surge in popularity and complexity. This incident is especially relevant as the MaaS cybercrime landscape continues to expand, driving rapid adoption of infostealer toolkits like StealC. Security teams must remain vigilant to emerging attacker tradecraft and vulnerabilities, as both operators and defenders look to exploit weaknesses in rival infrastructure.
8 months ago
Kill Chain
Unpacking the Kimwolf & AISURU Botnet: How 2 Million Android Devices Became a DDoS Army
In late 2025, security researchers at Lumen’s Black Lotus Labs null-routed traffic to over 550 command-and-control (C2) servers associated with the rapidly expanding Kimwolf and AISURU botnets. These botnets primarily targeted Android TV streaming devices—especially those with exposed ADB services—and used a malicious SDK (ByteConnect) to conscript over two million devices into a powerful residential proxy network. Threat actors leveraged this massive bot army to launch distributed denial-of-service (DDoS) attacks and facilitate malicious relay of internet traffic, further monetizing access via underground proxy services marketed on Discord and other platforms. The botnets exhibited rapid growth, exploiting security flaws in both consumer hardware and third-party proxy services for propagation. This incident highlights a shift in cybercriminal tactics toward wielding residential IP addresses for nefarious activity, circumventing traditional detection and blocking mechanisms. The scale and sophistication of these campaigns underscore escalating risks to organizations relying on residential endpoints and underscore the urgency for improved segmentation, anomaly detection, and real-time response.
8 months ago
Kill Chain
Apex Legends Live Character Hijack: 2026 Gaming Platform Breach Explained
In January 2026, Apex Legends players experienced a major security incident where an external threat actor gained unauthorized control over live player characters during matches. The attacker remotely hijacked user avatars, disconnected players from servers, and manipulated in-game identities, temporarily disrupting the gaming experience for tens of thousands. Respawn Entertainment, the game's publisher, confirmed the attack but stated there was no evidence of remote code execution or malware. Investigation pointed to exploitation of privileged backend debugging or admin interfaces, rather than a software vulnerability affecting all client machines. This incident underscores escalating threats targeting large-scale gaming platforms, where privilege escalation and endpoint attacks now rival phishing or malware techniques in their sophistication. With gaming ecosystems becoming lucrative and complex, attackers continue to innovate, highlighting the urgent need for improved internal traffic security and continuous monitoring.
8 months ago
Kill Chain
Instagram 2026: Data Scraping Leak Exposes 17 Million Accounts
In January 2026, security researchers and several hacking forums circulated claims that data for over 17 million Instagram accounts was leaked online. The incident is believed to stem from large-scale data scraping leveraging a password reset email bug, combined potentially with prior years' API vulnerabilities. The leaked dataset included a variety of personal information such as usernames, phone numbers, email addresses, and physical addresses. No passwords were exposed, and Meta (Instagram's parent company) denies that a system breach or new API compromise occurred, noting existing issues were promptly addressed and account security remains uncompromised. This case underscores the ongoing threat of data scraping and API abuse, where publicly accessible or insufficiently protected endpoints are targeted by cybercriminals. With the proliferation of social engineering attacks using scraped personal data and the repeated emergence of similar incidents across major platforms, the need for robust API security and user vigilance has never been greater.
8 months ago
Kill Chain
The Kimwolf & Aisuru Botnets: How Android TV Devices Fueled a Global Proxyware Crisis
In late 2025, the Kimwolf and Aisuru botnets collectively compromised over two million Android TV streaming boxes by leveraging factory-installed or bundled proxy malware. Attackers, operating through channels like Discord and Telegram, conscripted these devices for DDoS attacks, ad fraud, and mass content scraping. Investigations revealed overlapping cybercriminal operators, shared infrastructure, and direct monetization via residential proxy services such as Plainproxies, Maskify, and ByteConnect. The illicit operations exploited minimal device security, used decentralized technologies like Ethereum Name Service (ENS) for resilient command-and-control, and took advantage of poorly regulated server resellers in the U.S. and Europe. The incident underscores a rapidly evolving threat landscape where IoT/OTT devices are prime targets for distributed, difficult-to-mitigate botnets fueled by proxyware and privacy-invasive apps. It highlights urgent needs for better supply-chain security, IoT device hardening, and more robust detection and segmentation strategies to counter stealthy lateral movement and monetization tactics now seen across botnet campaigns.
8 months ago
Kill Chain
VVS Stealer: Obfuscated Python Malware Compromises Discord Accounts in 2025
In April 2025, researchers discovered a new information stealer, VVS Stealer, distributed via obfuscated Python code targeting Discord users. The malware, sold on Telegram, leverages Pyarmor obfuscation techniques to evade detection and focuses on harvesting Discord credentials and authentication tokens. Attackers propagated the malware through malicious campaigns that trick users into executing compromised scripts, resulting in unauthorized access to their Discord accounts. The impact was the loss of sensitive credentials, potential identity theft, and exposure of personal communications, with widespread risk for Discord communities and possibly further compromise of cloud-connected services. This incident exemplifies the growing sophistication in malware targeting online communities, particularly through social engineering and advanced obfuscation. There is a notable trend of threat actors exploiting popular platforms and leveraging encryption or evasion techniques to bypass standard security controls — elevating the urgency for endpoint protection, behavioral monitoring, and defense-in-depth controls.
8 months ago
Kill Chain
Kimwolf Botnet: When Residential Proxies Turn Your LAN Into a Global Attack Platform
In late 2025, a rapidly growing botnet called Kimwolf infected over two million devices worldwide, primarily through compromised Android TV boxes and digital photo frames lacking basic security controls or authentication. Attackers abused vulnerabilities in residential proxy networks—particularly via IPIDEA—to tunnel through external firewalls, gaining direct access to devices inside private networks. Kimwolf malware leveraged DNS tricks and default-enabled Android Debug Bridge (ADB) to enable lateral movement, turning victim devices into nodes for ad fraud, account takeovers, content scraping, and high-volume DDoS attacks, demonstrating unprecedented attacker reach into home and small business LANs. Kimwolf's swift expansion and post-takedown resilience reveal a new class of threats exploiting insecure IoT and overlooked network entry points inside residential and SMB environments. The incident highlights emerging risks from mass-produced, inadequately secured consumer tech and proxy networks, urging organizations to reconsider internal network trust assumptions and prioritize visibility, segmentation, and policy-driven controls to stop lateral movement and botnet proliferation.
8 months ago
Kill Chain
Evasive Panda: APT Delivers MgBot via DNS Poisoning in Asia (2022–2024)
Between November 2022 and November 2024, the Evasive Panda APT group executed a sophisticated campaign targeting victims primarily in Türkiye, China, and India. Leveraging adversary-in-the-middle (AitM) techniques and DNS poisoning, the attackers delivered a unique MgBot malware implant through fake software updates and stealthy loaders. The operation employed hybrid encryption, memory injection in signed executables, and evaded traditional defenses to maintain long-term persistence. Multiple new and legacy C2 infrastructures enabled sustained access while attackers tailored payloads based on the victim’s OS. This incident showcases the ongoing evolution of nation-state threat actors, utilizing advanced evasion, supply chain impersonation, and DNS manipulation to bypass security controls. It reflects a broader surge in attacks exploiting trust in software supply chains and underlines the need for continuously adaptive security strategies as actor sophistication grows.
8 months ago
Kill Chain
Critical 2025 UEFI Flaw Enables Pre-Boot DMA Attacks on Leading Motherboards
In December 2025, researchers from Riot Games identified a critical UEFI firmware vulnerability impacting motherboards from ASUS, Gigabyte, MSI, and ASRock. The flaw, tracked as CVE-2025-11901, CVE-2025‑14302, CVE-2025-14303, and CVE-2025-14304, allows Direct Memory Access (DMA) attacks during the pre-boot phase by bypassing IOMMU protections. Threat actors with physical access can attach malicious PCIe devices to read or alter system memory before the operating system loads, making traditional endpoint protections ineffective. The vulnerability was confirmed by multiple security advisories and coordinated with hardware vendors for urgent firmware updates. This incident highlights the increasing sophistication of firmware-level attacks that can evade operating system and security tool visibility. As hardware supply chains diversify and attackers target pre-boot processes, organizations face heightened risks in both enterprise and consumer hardware ecosystems.
8 months ago
Kill Chain
Inside Kimwolf: How 1.8 Million Android TVs Became a DDoS Botnet Army
In December 2025, cybersecurity researchers discovered the Kimwolf botnet had hijacked over 1.8 million Android-based smart TVs, set-top boxes, and tablets globally. The attackers leveraged the NDK (Native Development Kit) to compile malware that turned these consumer devices into a massive botnet used primarily for launching large-scale distributed denial-of-service (DDoS) attacks. The infected endpoints were recruited silently and spread across both residential and enterprise networks, enabling the attackers to conduct coordinated, high-bandwidth attacks and evade conventional network defenses. Initial findings also suggest a link between Kimwolf and the previously observed AISURU botnet, indicating possible collaboration or shared tooling between threat actors. This incident highlights a disturbing trend: threat actors increasingly targeting loosely protected IoT and smart device ecosystems for botnet creation. The scale and performance of Kimwolf underscore the growing risk posed by unpatched consumer electronics, calling for urgent improvements in east-west traffic security, segmentation, and network visibility across hybrid environments.
8 months ago
Kill Chain
SoundCloud 2024 Breach Exposes Member Data and VPN Vulnerabilities
In June 2024, SoundCloud experienced a significant security breach where threat actors compromised their infrastructure, resulting in outages and disruption of VPN connectivity. The attackers exfiltrated a database containing users' email addresses and profile information, exposing sensitive member data. The attack led to service interruptions that impacted both staff operations and user access, highlighting vulnerabilities in SoundCloud’s VPN and internal data security protocols. Subsequent investigations revealed that unencrypted network traffic and insufficient segmentation allowed the attackers to move laterally and extract confidential data. This incident exemplifies the growing trend of targeting cloud-based media platforms using sophisticated techniques, including exploiting VPN weaknesses and lateral movement within corporate networks. With regulatory scrutiny increasing around customer data privacy and the persistent rise in credential-driven breaches, organizations face mounting pressure to strengthen east-west security and encrypted network controls.
8 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Rapid Containment helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports