A fake torrent claiming to offer One Battle After Another has been used to spread malware by hiding malicious code inside subtitle files. Bitdefender researchers found the campaign after seeing a spike in detections tied to the film’s release. Attackers made the torrent look legitimate by including normal-looking files like the movie, cover images, and subtitles. A Windows shortcut disguised as a movie launcher triggered an encrypted PowerShell loader embedded inside the subtitle file. Once run, the infection chain ultimately loaded Agent Tesla into memory, enabling remote access and credential theft.
Relevant Source (CISA): Defending Against Malicious Cyber Activity Originating From Tor
CISA documents real-world malware campaigns delivered through pirated software shared on torrent services, matching the same core risk behind fake movie torrents.
Quick Facts
- Fake movie torrent spread malware through subtitle files
- Discovered by Bitdefender during a detection spike
- PowerShell code was hidden inside an .srt subtitle file
- Infection relied on a deceptive Windows shortcut
- Final payload was the Agent Tesla RAT
- Pirated movie torrents remain a common malware vector
Shortcut And Subtitle Malware
This attack is a malware distribution campaign that disguises itself as a popular movie torrent and uses subtitle files as a delivery mechanism. The torrent included a shortcut file that, when clicked, executed Windows commands to extract malicious PowerShell code hidden between specific lines of a subtitle file. That script reconstructed additional encrypted scripts and staged a multi-step infection process that ended with a memory-loaded malware payload.
- Uses a fake torrent for a newly released movie
- Hides encrypted PowerShell inside subtitle text
- Executes malware through a deceptive shortcut file
The technique stands out because subtitles are usually seen as harmless text files, which helps the malware evade casual inspection and some security tools.
Relevant Source (Microsoft): Backdoor:PowerShell/Sebona.A!dha Threat Description
Microsoft documents real-world cases where a Windows shortcut file embeds and launches PowerShell code, matching the same shortcut-triggered loader behavior described in your attack chain.
Why Torrent Malware Works
This campaign shows how malware delivery methods continue to evolve by exploiting user assumptions and file trust. Subtitles, images, and shortcuts are common in torrents, so users rarely question their presence. The infection chain also demonstrates how attackers blend native Windows tools with encrypted payloads to avoid detection and persist quietly. Even experienced users can be caught off guard when malware execution is indirect and layered.
- Targets interest in newly released movies
- Abuses trusted file types like .srt and .jpg
- Avoids obvious executables to reduce suspicion
- Uses scheduled tasks for persistence
- Loads final malware directly into memory
The result is credential theft, surveillance, and long-term compromise without clear warning signs.
Relevant Source (Microsoft): Tarrask Malware Uses Scheduled Tasks For Defense Evasion
Microsoft documents real-world malware persistence using hidden scheduled tasks and stealth techniques that match the same “quiet persistence” risk described here.
Steps After Torrent Exposure
Avoid downloading pirated movies, especially newly released titles that attract high interest and heavy seeding. Keep Windows security features enabled and updated, since attackers actively check for disabled defenses. Be cautious with shortcut files in downloads, as they are often used to trigger hidden commands. Treat unexpected subtitle or image files as potential attack surfaces, not harmless extras.
- Do not pirate new movies or TV shows
- Delete torrents containing shortcut files
- Keep Windows Defender or equivalent active
- Scan systems after risky downloads
- Change passwords if exposure is suspected
A single careless click can expose stored credentials across browsers, email clients, and VPN software.
Relevant Source (FBI): Pirated Software May Contain Malware
The FBI warns that pirated downloads can carry malware that steals passwords and personal data, which directly supports the advice to avoid piracy and treat unknown files as risky.
Old Malware, New Delivery
Agent Tesla has been active since at least 2014 and remains popular because it works reliably and is easy to deploy. Its continued use shows that attackers do not need new malware when proven tools still succeed. What changes is how the malware is delivered, not what it does once installed.
As long as high-demand entertainment drives torrent traffic, attackers will keep exploiting it. File formats that look harmless today can become tomorrow’s malware carriers, especially when combined with scripting and native system tools.
Relevant Source (Cisco Talos): SWEED: Exposing Years Of Agent Tesla Campaigns
Cisco Talos describes long-running Agent Tesla activity dating back to at least 2014 and shows how established stealers stay effective while delivery methods keep changing.
Torrent Familiarity Creates Risk
This incident reinforces a simple reality of modern malware distribution: familiarity breeds risk. Movie torrents often look routine, but attackers know exactly which files users will trust and open without hesitation. Staying safe means avoiding piracy, questioning unexpected files, and understanding that malware rarely announces itself with obvious warnings.
Relevant Source (INTERPOL): Digital Piracy
INTERPOL warns that pirated content on peer-to-peer networks can contain malware that harms devices and steals personal information, matching the risk message in your conclusion.
FAQ
How was malware hidden in subtitles?
Encrypted PowerShell code was embedded between specific lines in an .srt file and extracted at runtime.
What malware was installed?
The final payload was Agent Tesla, a Windows remote access trojan and credential stealer.
Why use a shortcut file?
Windows shortcuts can run commands silently, making them ideal for triggering hidden scripts.
Is Agent Tesla new?
No. It has been widely used since around 2014 due to its reliability.
Are only movie torrents affected?
No. Similar tactics appear in software cracks, games, and other pirated content.
How JENI Helps Protect Your System
Malware delivered through fake torrents works because it hides in places most users never check. Subtitle files, image files, and shortcuts blend into normal downloads and quietly trigger system level abuse. Cleaning up after these infections requires more than deleting the visible files.
How JENI Reduces Risk
- Scans and clears hidden script remnants left behind by malware loaders
- Repairs Windows components commonly abused by PowerShell based attacks
- Detects system instability caused by scheduled tasks and background persistence
JENI focuses on restoring system integrity after exposure rather than chasing scare tactics. It runs locally, uses trusted repair methods, and does not rely on cloud scanning or data collection. Malware like Agent Tesla leaves behind broken caches, altered tasks, and damaged system state. Addressing those issues early reduces long term credential risk and system instability without adding noise or complexity.

