Cybercriminals are leveraging the popularity of a new Leonardo DiCaprio film, 'One Battle After Another,' to distribute the Agent Tesla remote access trojan (RAT) through malicious movie torrents. Victims searching for the film online are tricked into downloading a folder containing seemingly legitimate files, including a shortcut file (CD.lnk) and a subtitle file (Part2.subtitles.srt). When the shortcut is executed, it triggers a multi-stage attack that uses hidden batch code within specific lines of the subtitle file to launch PowerShell scripts, ultimately installing Agent Tesla on the victim's Windows system. The attack is designed to run entirely in memory, using legitimate Windows tools such as CMD, PowerShell, and Task Scheduler to evade detection by traditional security software.
Bitdefender researchers identified this campaign after observing a spike in detections linked to the fake movie torrent. The malware deployment process involves multiple layers of encryption and code obfuscation, with malicious scripts embedded in files that otherwise appear harmless. Once installed, Agent Tesla grants attackers full remote access to the infected device, enabling the theft of personal and financial information. The campaign has already impacted thousands of users, highlighting the ongoing risks associated with downloading pirated content from untrusted sources.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Bitdefender observed that the same or similar torrent-based lures were also used in related campaigns delivering other malware, including Lumma Stealer. This showed the technique was part of a broader pattern of abusing pirated media downloads for malware distribution.
Attackers distributed a fake movie torrent containing a malicious LNK file and subtitle files with hidden PowerShell code that launched a multi-stage infection chain. The payload was Agent Tesla, deployed in memory using legitimate Windows tools, scheduled tasks, and concealed files to evade detection and steal credentials.
Bitdefender researchers uncovered a malware campaign abusing fake torrents for Leonardo DiCaprio’s film 'One Battle After Another' to infect users. The campaign was identified after researchers observed a spike in related detections and found the torrent had attracted thousands of seeders and leechers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.