• News/
  • https://www.bleepingcomputer.com/news/security/fake-one-battle-after-another-torrent-hides-malware-in-subtitles/

Fake ‘One Battle After Another’ torrent hides malware in subtitles

BleepingComputer
·
Bill Toulas
·
Published Dec 12, 2025
·
Updated

A fake torrent for Leonardo DiCaprio’s 'One Battle After Another' hides malicious PowerShell malware loaders inside subtitle files that ultimately infect devices with the Agent Tesla RAT malware. The malicious torrent file was discovered by Bitdefender researchers while investigating a spike in detections related to the movie. One Battle After Another is a highly rated Paul Thomas Anderson movie released on September 26, 2025, starring Leonardo DiCaprio, Sean Penn, and Benicio del Toro. Cybercriminals taking advantage of interest around new movies by uploading malicious torrents isn't anything new, but Bitdefender notes this case stands out for its unusually complex and stealthy infection chain. "It's impossible to estimate how many people downloaded the files, but we saw that the supposed movie had thousands of seeders and leechers," explained Bitdefender. The downloaded One Battle After Another movie torrent used in the attacks contains various files, including a movie file (One Battle After Another.m2ts), two image files (Photo.jpg, Cover.jpg), a subtitles file (Part2.subtitles.srt), and a shortcut file (CD.lnk) that appears as a movie launcher. When the CD shortcut is executed, it launches Windows commands that extract and run a malicious PowerShell script embedded in the subtitle file between lines 100 and 103. This PowerShell script will then extract numerous AES-encrypted data blocks from the subtitles file again to reconstruct five PowerShell scripts that are dropped...

Read full article

Affected Software

1 affected component
Microsoft PowerShell
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a fake torrent for the movie 'One Battle After Another' that hides malware in subtitle files.

2

What type of malware is spread through the fake torrent?

The fake torrent spreads the Agent Tesla RAT malware through malicious PowerShell loaders.

3

Who discovered the malicious torrent file?

Bitdefender researchers discovered the malicious torrent file during their investigation.

4

What software is primarily affected by the malware hidden in the torrent?

The malware primarily affects devices using Microsoft PowerShell.

5

What is the risk associated with downloading subtitles from this torrent?

Downloading subtitles from this torrent can lead to device infection with malicious malware.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203