“`html

“One Battle After Another” Torrent Infects Users with AgentTesla RAT

In a sophisticated campaign, threat actors are leveraging a malicious torrent disguised as the highly anticipated film “One Battle After Another” to distribute the AgentTesla remote access trojan (RAT). Security researchers estimate the torrent has been downloaded by thousands of users. Attribution confidence is high, given the malware’s signature and delivery mechanism.

The Attack

The infection chain begins with a user downloading the fraudulent torrent file. This archive contains a seemingly innocuous set of files, including the film file itself, image files, and a subtitle file (Part2.subtitles.srt). A malicious shortcut file (CD.lnk) is also present, designed to appear as the film launcher. Upon execution, the shortcut leverages Windows commands to extract and execute a PowerShell script embedded within the subtitle file.

This embedded PowerShell script is the key to the attack. It extracts AES-encrypted data blocks from the subtitle file and reconstructs five additional PowerShell scripts that are dropped into the “C:\Users\\AppData\Local\Microsoft\Diagnostics” directory. These scripts then initiate a multi-stage process that includes checking for Windows Defender, installing Go, and ultimately loading the AgentTesla payload directly into the computer’s memory. The use of a subtitle file to conceal malicious code demonstrates a clever evasion tactic designed to bypass traditional security measures.

The Actors

While the specific actors behind this campaign are yet unknown, the use of AgentTesla points to an established group or affiliate network. AgentTesla is a well-known Windows RAT and information stealer that has been active since 2014. It is widely used to pilfer sensitive data such as browser credentials, email accounts, FTP login information, and VPN credentials. The malware’s longevity and ease of deployment make it a popular choice among cybercriminals. This campaign also highlights the continuing exploitation of current movie releases and torrent websites.

The Fallout

Victims face potential compromise of their systems and the theft of sensitive data. AgentTesla’s capabilities enable the attackers to monitor user activity, steal passwords, and potentially gain further access to corporate networks. The exact number of infected users is impossible to determine, however, the fact that the torrent had thousands of seeders and leechers increases the attack’s scope. Financial losses could include the cost of incident response, malware removal, and potential data breach notification expenses. Further damage includes reputational harm.

While there are no reports of a ransom being demanded, the stolen data can be used for financial crimes such as identity theft and extortion. Law enforcement agencies are surely tracking the actors’ infrastructure, although no information on investigations has been released yet.

Cybercrime Economics

  • Cost of Attack: Minimal. Torrent distribution is essentially free. The primary expense would be the development of the PowerShell scripts, but since the AgentTesla malware has been around for some time, it is easy to acquire.
  • Potential Payout: Dependent on the value of the stolen credentials and the potential for secondary exploitation (e.g., selling access, ransomware deployment).
  • Affiliate Revenue Share: Unknown in this specific case, but typically the affiliate receives a percentage of profits from the data or services sold (e.g., access to compromised systems).

“`


Leave a Reply

Your email address will not be published. Required fields are marked *