← Back to BrewedIntel
malwarehighInfostealerSocial EngineeringAgent Tesla

Dec 10, 2025 • Raul Vasile BUCUR

Fake Leonardo DiCaprio Movie Torrent Drops Agent Tesla Through Layered PowerShell Chain

Bitdefender researchers identified a malicious campaign distributing the Agent Tesla infostealer via fake torrent files posing as Leonardo DiCaprio's latest...

Source
Bitdefender Labs
Category
malware
Severity
high

Executive Summary

Bitdefender researchers identified a malicious campaign distributing the Agent Tesla infostealer via fake torrent files posing as Leonardo DiCaprio's latest film, One Battle After Another. The infection utilizes a layered PowerShell chain to execute the payload upon user interaction. This social engineering tactic exploits public interest in new movie releases to bypass security awareness. Agent Tesla is a known information stealer capable of harvesting credentials, cookies, and cryptocurrency wallet data, posing a significant risk to individual users and organizations. The severity is rated high due to the effectiveness of entertainment-based lures. Users are advised to avoid downloading copyrighted content from unofficial sources and maintain updated endpoint protection. Security teams should monitor for suspicious PowerShell execution chains and block known Agent Tesla indicators. This campaign highlights the ongoing risk of pirated media as a vector for malware distribution.

Summary

After noticing a spike in detections involving what looked like a movie torrent for One Battle After Another, Bitdefender researchers started an investigation and discovered that it was a complex infection chain. The film, Leonardo DiCaprio's latest, has quickly gained notoriety, making it an attractive lure for cybercriminals seeking to infect as many devices as possible. People often search for the latest movies on the internet, hoping to find a copy of a new release that has just begun its

Published Analysis

Bitdefender researchers identified a malicious campaign distributing the Agent Tesla infostealer via fake torrent files posing as Leonardo DiCaprio's latest film, One Battle After Another. The infection utilizes a layered PowerShell chain to execute the payload upon user interaction. This social engineering tactic exploits public interest in new movie releases to bypass security awareness. Agent Tesla is a known information stealer capable of harvesting credentials, cookies, and cryptocurrency wallet data, posing a significant risk to individual users and organizations. The severity is rated high due to the effectiveness of entertainment-based lures. Users are advised to avoid downloading copyrighted content from unofficial sources and maintain updated endpoint protection. Security teams should monitor for suspicious PowerShell execution chains and block known Agent Tesla indicators. This campaign highlights the ongoing risk of pirated media as a vector for malware distribution. After noticing a spike in detections involving what looked like a movie torrent for One Battle After Another, Bitdefender researchers started an investigation and discovered that it was a complex infection chain. The film, Leonardo DiCaprio's latest, has quickly gained notoriety, making it an attractive lure for cybercriminals seeking to infect as many devices as possible. People often search for the latest movies on the internet, hoping to find a copy of a new release that has just begun its After noticing a spike in detections involving what looked like a movie torrent for One Battle After Another, Bitdefender researchers started an investigation and discovered that it was a complex infection chain. The film, Leonardo DiCaprio's latest, has quickly gained notoriety, making it an attractive lure for cybercriminals seeking to infect as many devices as possible. People often search for the latest movies on the internet, hoping to find a copy of a new release that has just begun its

Linked Entities

  • Agent Tesla