Dec 10, 2025 • Raul Vasile BUCUR
Fake Leonardo DiCaprio Movie Torrent Drops Agent Tesla Through Layered PowerShell Chain
Bitdefender researchers identified a malicious campaign distributing the Agent Tesla infostealer via fake torrent files posing as Leonardo DiCaprio's latest...
Executive Summary
Bitdefender researchers identified a malicious campaign distributing the Agent Tesla infostealer via fake torrent files posing as Leonardo DiCaprio's latest film, One Battle After Another. The infection utilizes a layered PowerShell chain to execute the payload upon user interaction. This social engineering tactic exploits public interest in new movie releases to bypass security awareness. Agent Tesla is a known information stealer capable of harvesting credentials, cookies, and cryptocurrency wallet data, posing a significant risk to individual users and organizations. The severity is rated high due to the effectiveness of entertainment-based lures. Users are advised to avoid downloading copyrighted content from unofficial sources and maintain updated endpoint protection. Security teams should monitor for suspicious PowerShell execution chains and block known Agent Tesla indicators. This campaign highlights the ongoing risk of pirated media as a vector for malware distribution.
Summary
After noticing a spike in detections involving what looked like a movie torrent for One Battle After Another, Bitdefender researchers started an investigation and discovered that it was a complex infection chain. The film, Leonardo DiCaprio's latest, has quickly gained notoriety, making it an attractive lure for cybercriminals seeking to infect as many devices as possible. People often search for the latest movies on the internet, hoping to find a copy of a new release that has just begun its
Published Analysis
Bitdefender researchers identified a malicious campaign distributing the Agent Tesla infostealer via fake torrent files posing as Leonardo DiCaprio's latest film, One Battle After Another. The infection utilizes a layered PowerShell chain to execute the payload upon user interaction. This social engineering tactic exploits public interest in new movie releases to bypass security awareness. Agent Tesla is a known information stealer capable of harvesting credentials, cookies, and cryptocurrency wallet data, posing a significant risk to individual users and organizations. The severity is rated high due to the effectiveness of entertainment-based lures. Users are advised to avoid downloading copyrighted content from unofficial sources and maintain updated endpoint protection. Security teams should monitor for suspicious PowerShell execution chains and block known Agent Tesla indicators. This campaign highlights the ongoing risk of pirated media as a vector for malware distribution. After noticing a spike in detections involving what looked like a movie torrent for One Battle After Another, Bitdefender researchers started an investigation and discovered that it was a complex infection chain. The film, Leonardo DiCaprio's latest, has quickly gained notoriety, making it an attractive lure for cybercriminals seeking to infect as many devices as possible. People often search for the latest movies on the internet, hoping to find a copy of a new release that has just begun its After noticing a spike in detections involving what looked like a movie torrent for One Battle After Another, Bitdefender researchers started an investigation and discovered that it was a complex infection chain. The film, Leonardo DiCaprio's latest, has quickly gained notoriety, making it an attractive lure for cybercriminals seeking to infect as many devices as possible. People often search for the latest movies on the internet, hoping to find a copy of a new release that has just begun its
Linked Entities
- Agent Tesla