Drooid Logo
Back to story perspectives

Full Breakdown

Cybercriminals Exploit Leonardo DiCaprio Film to Distribute Agent Tesla Malware

12/12/2025, 11:13:48 PM

Overview of the Cyberattack

Cybercriminals have leveraged the popularity of Leonardo DiCaprio's film, *One Battle After Another*, to disseminate the Agent Tesla Remote Access Trojan (RAT) through a sophisticated torrent-based infection chain. This attack was identified by researchers at Bitdefender, who noted a significant increase in malware detections associated with a torrent that falsely claimed to offer the new movie. Instead of delivering legitimate video content, the torrent initiates a multi-layered fileless malware attack that ultimately installs Agent Tesla, a powerful tool designed for persistent surveillance and credential theft.

Mechanism of Infection

The infection process begins when a user downloads a torrent file masquerading as a pirated copy of *One Battle After Another*. Within this torrent lies a file named CD.lnk, which appears to be a shortcut to the film but is, in fact, a decoy. Executing this file triggers a malicious script chain using legitimate Windows tools such as cmd.exe, PowerShell, and Task Scheduler. The shortcut reads specific lines from a seemingly benign subtitle file (Part2.subtitles.srt) that contains hidden batch code. This code executes PowerShell commands to extract and decrypt additional malicious payloads embedded in other disguised files, including a fake video file and password-protected archives.

The final payload, Agent Tesla, is notorious for its capabilities in keylogging, clipboard monitoring, screen capturing, and credential harvesting. The malware achieves persistence by creating a scheduled task named RealtekDiagnostics, which masquerades as an audio helper tool, ensuring that the infection remains undetected.

Implications for Users

The attack appears opportunistic, primarily targeting novice users who may not recognize the risks associated with torrenting. The torrent file reportedly had thousands of seeders and leechers, indicating a large pool of potential victims. This incident underscores the ongoing threat of malware disguised as popular entertainment content and highlights the need for users to exercise caution when downloading unauthorized files.

Official Statements & Responses

Bitdefender researchers emphasize the importance of avoiding pirated content and recommend scanning downloaded files with updated antivirus software. They also advise users to monitor scheduled tasks for any suspicious entries, such as 'RealtekDiagnostics,' which could indicate a malware infection.

Criticism & Opposition

Cybersecurity experts have criticized the reliance on traditional security measures, noting that the use of Living Off the Land (LOTL) techniques and in-memory execution complicates detection efforts. This incident calls for enhanced threat detection methods to address evolving cyberattack strategies.

Verbatim Quotes

  • “The use of LOTL techniques and in-memory execution makes detection challenging for traditional security software.” — Cybersecurity Expert, HackRead

Conflicting Reports & Gaps

While the primary focus of the attack is clear, there is limited information regarding the specific scale of the infection or the number of victims affected. Further investigation may be required to fully understand the impact of this cyberattack.