Cybercriminals Are Hiding New Malware in Torrents for Popular Films
Recorded: Sept. 21, 2026, 8 p.m.
| Original | Summarized |
Cybercriminals Hiding New Malware in Torrents for Popular Films Informa TechTarget|Cybersecurity DiveInformationWeekChannel DiveTechTarget: CybersecurityExplore our brandsAn Informa TechTarget PublicationDark Reading Resource LibraryBlack Hat NewsOmdia CybersecurityAdvertiseNewsletter Sign-UpNewsletter Sign-UpCybersecurity TopicsRelated TopicsApplication SecurityCybersecurity CareersCloud SecurityCyber RiskCyberattacks & Data BreachesCybersecurity AnalyticsCybersecurity OperationsData PrivacyEndpoint SecurityICS/OT SecurityIdentity & Access Mgmt SecurityInsider ThreatsIoTMobile SecurityPerimeterPhysical SecurityRemote WorkforceThreat IntelligenceVulnerabilities & ThreatsRecent in Cybersecurity TopicsVulnerabilities & ThreatsCisco Zero-Day Highlights API Endpoint Authentication IssuesCisco Zero-Day Highlights API Endpoint Authentication IssuesbyRob WrightSep 18, 20264 Min ReadCybersecurity OperationsAI Security Spending Jumps as Fear Outpaces Proof of ValueAI Security Spending Jumps as Fear Outpaces Proof of ValuebyJai VijayanSep 16, 20265 Min ReadWorld Related TopicsDR GlobalAsia PacificEuropeLatin AmericaMiddle East & AfricaSee AllThe EdgeDR TechnologyEventsRelated TopicsUpcoming EventsPodcastsWebinarsSEE ALLResourcesRelated TopicsResource LibraryWhite PapersReportsWebinarsNewslettersPodcastsHeard It From a CISOReporters' NotebookDark Reading's 20thVideosDark Reading PollsPartner PerspectivesMeet the EditorsAdvertise With Us About UsDark Reading Resource LibraryCyberattacks & Data BreachesCyber RiskVulnerabilities & ThreatsPress ReleasesCybercriminals Are Hiding New Malware in Torrents for Popular FilmsVictims have been identified in Africa, including in Kenya and Uganda.September 21, 20264 Min ReadPRESS RELEASENAIROBI, Kenya , September 21, 2026 — Kaspersky's Global Research and Analysis Team (GReAT) has uncovered a sophisticated new multi-stage campaign targeting both individual users and organisations. The campaign relies on a previously unknown malware strain distributed through torrent trackers disguised as popular films, including The Odyssey. One of the popular public archives of torrent files was compromised and was then used to deliver the malicious payload. Several hundred victims have been identified in a multitude of countries, including Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries such as Spain, the Netherlands, Belgium, Germany and others. Victims already identified include organisations operating in the enterprise, government, IT, consulting, retail, transportation, and agriculture sectors. The campaign has been active since at least mid-August and remains ongoing.Related:Vectra AI Launches Ascent to Help Address New Era of AI-Driven AttacksThe attack itself is built as a multi-stage framework composed of several elements that work together at different stages of the intrusion. At the initial stage, the malware uses a loader capable of detecting antivirus sandboxes, which are isolated testing environments security products use to safely examine suspicious files. This allows the malware to determine whether it is being analysed and, if so, evade detection or hinder further investigation. Once active on a victim’s device, the malware deploys additional modules that expand its capabilities. These modules allow it to establish persistence, so it remains on the system after a reboot even after it has been terminated, bypass User Account Control (UAC) to gain administrator privileges in Windows without triggering the usual warning prompt and ultimately provide the attackers with remote access to the compromised machine.To retrieve the address of its command-and-control server, the malware uses the Solana blockchain. This gives the attackers a more resilient way to maintain control over their infrastructure and makes the campaign harder to disrupt through blocking or takedown efforts.“The campaign is notable for combining a common lure with a sophisticated technical design. By disguising malware as torrents for popular films, the attackers increase the likelihood that unsuspecting users will download it. Once launched, the multi-stage malware is designed to evade detection, establish persistence, and provide the attackers with remote access to infected devices. Users should be especially cautious with files downloaded from unofficial sources, as even seemingly harmless entertainment content can serve as a vehicle for compromise,” says Konstantin Isakov, security expert at Kaspersky GReAT.Related:EY Survey Finds Autonomous AI Implementation Outpaces OversightTo stay safe Kaspersky recommends that users:Be cautious with downloads. It’s safer to install games and mods only from official sources or reputable websites. Unofficial sources may contain malware.Use a strong security solution, such as Kaspersky Premium, on all computers and mobile devices. It will warn you about potential threats and prevent infection.Never disable antivirus or security tools to download any files or software.Organisations are recommended to:Implement clear guidelines for the use of third-party software on work devices.Use all-encompassing solutions from the Kaspersky Next product line that provide real-time protection, threat visibility, and the investigation and response capabilities of EPP, EDR and XDR. Depending on your current needs and available resources, you can choose the most relevant solution within this product line and easily migrate to another one if your cybersecurity requirements change.Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organisation. The latest Kaspersky Threat Intelligence will provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner.If your company lacks cybersecurity expertise, adopt managed security services from Kaspersky such as Compromise Assessment, Managed Detection and Response, and/or Incident Response, which cover the entire incident management cycle – from threat identification to continuous protection and remediation.Related:AI Agent Breaches Spanish Organization, Modifies Personal DataKaspersky security solutions detect the described malware. The full technical analysis is available on www.Securelist.com.About KasperskyKaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date. Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support. Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at (www.Kaspersky.co.za).Want more Dark Reading stories in your Google search results?Add Us NowMore InsightsIndustry ReportsThe State of Cloud Security: The Latest ChallengesHow Organizations Are Managing Incident ResponseHow Enterprises Are Developing Secure ApplicationsInside RSAC 2026: security leaders reveal the risks redefining your defense strategyEssential News & Insights from Black Hat USA 2025Access More ResearchWebinarsEffective Alert Triage: Reducing Noise and Finding Real ThreatsCybersecurity Outlook 2027Threat Exposure Analytics: Measuring and Communicating Security RiskBenchmark Scores Are a False FlagBuilding an Effective Red Team: Beyond Penetration TestingMore WebinarsFeaturedCheck out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!Editor's ChoiceCyber RiskAnthropic CEO: Time to Shift From Improving to Controlling AIAnthropic CEO: Time to Shift From Improving to Controlling AIbyElizabeth MontalbanoSep 14, 20266 Min ReadCyber RiskWhy AI Is So Good at Scamming HumansWhy AI Is So Good at Scamming HumansSep 11, 2026Want more Dark Reading stories in your Google search results?November 12, 2026 | VIRTUALWhat Every Enterprise Should Know About Securing Cloud Assets In the Age of AISave Your SpotKeep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.SubscribeDiscover MoreBlack HatOmdiaWorking With UsAbout UsMeet the EditorsAdvertiseReprintsJoin UsNewsletter Sign-UpFollow UsCopyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.Home|Cookie Policy|Privacy|Terms of UseYour Privacy Choices |
Kaspersky's Global Research and Analysis Team (GReAT) has identified a sophisticated, multi-stage cyber campaign that distributes a previously unknown malware strain by disguising it within torrent trackers containing popular films, such as The Odyssey. This malicious payload was delivered through compromised public archives of torrent files, resulting in the identification of several hundred victims across numerous countries, including Russia, Türkiye, Japan, Kenya, Uganda, Colombia, and various European nations such as Spain, the Netherlands, Belgium, and Germany. The affected entities span multiple sectors, including organizations in the enterprise, government, IT, consulting, retail, transportation, and agriculture. The campaign has been active since at least mid-August and remains ongoing. The technical structure of the attack is built upon a multi-stage framework designed for evasion and control. Initially, the malware employs a loader capable of detecting antivirus sandboxes, which are security testing environments used to examine suspicious files, enabling the malware to evade detection or impede investigation if it suspects analysis is taking place. Once active on a victim's system, the malware deploys additional modules to establish persistence, ensuring it remains installed across reboots and survives termination. Furthermore, it bypasses User Account Control (UAC) protocols to achieve administrator privileges on Windows without triggering standard warnings, thereby granting the attackers remote access to the compromised machine. To maintain resilient control over their infrastructure, the malware utilizes the Solana blockchain to locate the address of its command-and-control server, making the campaign more difficult to disrupt through blocking or takedown efforts. Security expert Konstantin Isakov from Kaspersky GReAT noted that the campaign is notable for effectively combining a common lure, like torrents for films, with a highly sophisticated technical design to maximize the probability that unsuspecting users will download the malware. The entire sequence of the multi-stage malware is engineered to evade detection, establish persistence, and provide remote access to infected devices simultaneously. In response to these threats, Kaspersky offers specific recommendations for users and organizations. Individuals are advised to exercise extreme caution regarding downloads, recommending that games and mods be installed only from official sources or reputable websites, as unofficial sources often contain malware. It is also crucial never to disable antivirus or security tools when downloading any files or software. For organizations, the recommendation is to implement clear guidelines governing the use of third-party software on work devices. Furthermore, entities are encouraged to adopt comprehensive solutions from the Kaspersky Next product line, which provide real-time protection, threat visibility, and capabilities for investigation and response through Endpoint Protection, Endpoint Detection and Response, and Extended Detection and Response. If an organization lacks in-house cybersecurity expertise, adopting managed security services, such as Compromise Assessment, Managed Detection and Response, and/or Incident Response, is recommended to cover the entire incident management cycle. The latest Kaspersky Threat Intelligence is also provided to security professionals, offering rich context across the entire incident management cycle to facilitate timely identification of cyber risks. |