Threat actors have leveraged popular creative content platforms and multimedia files to distribute infostealer malware to unsuspecting users. In one case, attackers uploaded free 3D model files containing malicious Python scripts to the CGTrader marketplace for use with the open-source Blender software. If users had Blender's "Auto Run Python Scripts" feature enabled, simply opening the .blend file would execute the embedded script, which then connected to a remote server to download a malware loader, ultimately infecting the system with the StealC V2 infostealer. This attack highlights the risks associated with open-source tools that allow automation and the lack of security controls on user-generated content marketplaces.
In a separate but thematically similar incident, Bitdefender researchers discovered a torrent file for the movie "One Battle After Another" that was used to deliver the Agent Tesla malware. The attack chain began when users launched a shortcut file included in the torrent, which triggered a series of PowerShell scripts hidden within a subtitle file. These scripts extracted and executed additional payloads from other files in the torrent, ultimately running the Agent Tesla infostealer entirely in memory to evade detection. Both incidents demonstrate the increasing sophistication of malware delivery methods that exploit trusted creative and entertainment platforms, targeting users through seemingly legitimate files and leveraging features like script automation and file embedding.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Bitdefender researchers uncovered a malware campaign using a fake torrent for the Leonardo DiCaprio film 'One Battle After Another' to target Windows users. The attack hid malicious code in subtitle files, abused legitimate Windows tools for execution, and ultimately deployed the Agent Tesla RAT.
A threat actor distributed free Blender .blend model files on CGTrader containing embedded malicious Python scripts. When opened with Blender's Auto Run Python Scripts feature enabled, the files executed code that downloaded a loader via Cloudflare Workers and infected victims with the StealC V2 infostealer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.