Prom3th3uS, a trusted user on TPB, is uploading torrents bundled with RATs.
I'm going to copy my report from TPB forums/report a torrent forum.
"Start11/Stardock from their upload page dropped a trojan that used screenconnect to attempt to call out and exfiltrate data. I just finished cleaning this up, it was dialing out to edgeserv.ru. This malware sat on my PC for almost a year before attempting to dial out, installed in 2025. It didnt start to dial out until june 21 2026 thankfully and i was able to catch it right away but man this was a close one.
You have a TRUSTED user uploading cracks with trojans bundled into them. Do you have any idea how messed up it is that a trusted user is allowed to upload trojans for over a year with impunity?
How many others got infected because a trusted user decided to bundle malware into their legitimate uploads with a trusted account on your platform?
You guys need to take action on this, they're still uploading files as of today. Still trusted status. Download the stardock/start11 torrent and scan the executables in virustotal and check the behavior pages, you'll see the same things i saw. I would do it for you but i don't want to redownload malware on purpose.
Long term user, this is the only thing that has ever actually gotten me infected with a RAT. They need their trusted status stripped, hopefully banned, and their uploads removed from your database.
Here's some extra stuff:
Network / C2 Infrastructure
C2 Domain: Code: edgeserv.ru C2 Destination IP: Code: 95.214.234.238 C2 Port: Code: 8041 (TCP) Traffic Pattern: Regular outbound beaconing/handshake attempts every 30 to 60 minutes initiated by background client services.
Dropped Binaries & Masqueraded Paths
Malicious Install Directory: Code: C:\Program Files (x86)\Windows VC
(masquerading as Microsoft Visual C++) Dropped Executables: Code: ScreenConnect.ClientService.exe Code: ScreenConnect.WindowsClient.exe Service Name / Masquerade: ScreenConnect Client registered under the guise of "Visual C++" to persist across reboots under Code: LocalSystem / Code: SYSTEM privileges.Bundled Installer & Heuristic Detections
Patch Binary: Code: ...\Stardock\Start11\x64-patch.exe (Flags as Code: HackTool:Win32/Keygen ) Cached Installer Artifact: Code: C:\Windows\Installer[random].msi Threat Classification: Code: Trojan:Win32/Malgent!MTB / Code: PUA:Win32/ConnectWise Attack Method: Abuse of legitimate remote management software (ScreenConnect/ConnectWise Control). The repackaged installer quietly provisions a persistent background service pointing to unauthorized third-party infrastructure ( Code: edgeserv.ru / Code: 95.214.234.238 ) during the cracked software setup."
TL;DR a trusted user is uploading malware bundled with software cracks, the malware tries to dial out to the above details. I got hit from stardock/Start11, but there are multiple reports on reddit in the various subreddits of people getting RATs from their cracks.
They were trusted at one point, but does that really matter if they're now bundling malware into their cracks? Their seed statistics on their most seeded torrents also look incredibly sus, they go from 100 to 1xxx and they all sit at around the same seed count.
If i had to guess, the original guy sold his account or got hacked and people have continued to upload malware bundled into their cracks since then on the account to abuse the trusted status icon.
Stay away from anything this user uploads, hopefully the mods on the site can remove their status and torrents.
Edit: virustotal links/behavior, Main installer EXE- https://www.virustotal.com/gui/file/360455f3671b766a683b56dfc825fb3355b538cc1f1b8391a1b22e19f07d2f27/behavior
Secondary patch- https://www.virustotal.com/gui/file/ccbe694ce564c5c8bbcd6922693c7001dd774381ece53ca3f787ec652f32a64b/detection
Main installer is the infected one, you can see it under the behavior tab. You'll see edgeserv.ru as the C2 server, the patch is just included on my post to be thorough so im linking it here, too.