Hackers are exploiting public interest surrounding allegations against rapper Sean “Diddy” Combs, using the malware PDiddySploit.

As Diddy faces serious charges of extortion, sexual assault, and other forms of violence, cybercriminals are taking advantage of the public's curiosity. Since September 13, threats have been tricking users into downloading infected files purporting to contain posts and replies from Diddy's deleted X account .
Read more: Cloudflare: Warns of hacking gang targeting Asia
The malicious payload has been modified by the PySilon remote access trojan, an advanced malware written in Python. This variant of the trojan is called PDiddySploit.
This malware has the ability to steal sensitive information, record keystrokes, monitor screen activity, and execute remote commands, leading to a complete compromise of a system and its users. According to VirusTotal data, most security vendors have not yet detected this new malware.
"As public attention peaks around this story, cybercriminals are taking the opportunity to trick unsuspecting users into downloading malicious files, exposing you to cyber threats," Veriti researchers warn.
"The fact that P. Diddy and others have deleted their social media content adds an extra layer of mystery, tempting users to open these files to discover what has been deleted.".
See more: The dark side of Influencer culture – When fame becomes a target for cybercrime
Since the strain first appeared in 2023, the PySilon RAT has already had over 300 different variants. Researchers expect more hackers to try to exploit the malware, following the recent success of PDiddySploit.
The most effective protection is to avoid executing infected files. Users should be cautious and avoid downloading suspicious documents, first confirming the source and scanning the document with multiple antivirus solutions. Infected files are often spread through email attachments or links.
“While it’s natural to be interested in current affairs and celebrity scandals, it’s important to be cautious when interacting with any relevant file or content online,” Veriti warns. “Check for signs of tampering: if a file seems too good to be true – like an offer of exclusive content from a deleted account – it’s probably a trap.”

Read also: PIXHELL: Steals data from Air-Gapped computers
This isn't the first time hackers have exploited Diddy's name. In 2013, a malicious file related to his song "I'm Coming Home" was distributed disguised as an MP3, with the title "Diddy & Dirty Money – I'm Coming Home (feat. Skylar Grey).mp3.pif." This attack involved a program information file (PIF) from the MS-DOS era.
Source: cybernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
