www.darkreading.com 21 Sept 2026, 19:11 UTC

Kaspersky Uncovers Malware Campaign Hidden in Film Torrents

Kaspersky Uncovers Malware Campaign Hidden in Film Torrents
CyberSIXT Evidence Panel Source marked as original reporting

KASPERSKY’S Global Research and Analysis Team (GReAT) says it has identified an ongoing, multi-stage malware campaign that has been active since at least mid-August 2026. The previously unknown malware is distributed through torrent trackers disguised as popular films, including *The Odyssey*. Kaspersky said one popular public torrent archive was compromised and used to deliver the malicious payload.

Several hundred victims have been identified across countries including Russia, Türkiye, Japan, Kenya, Uganda, Colombia, Spain, the Netherlands and Belgium. Affected organisations span enterprise, government, IT, consulting, retail, transport and agriculture sectors.

The malware reportedly begins with a loader that can detect antivirus sandboxes, helping it evade analysis. Once running, additional modules establish persistence, bypass Windows User Account Control (UAC) to obtain administrator privileges without the usual warning, and provide attackers with remote access to the infected device.

The campaign also uses the Solana blockchain to retrieve the address of its command-and-control server, giving the operators a more resilient method of maintaining control and complicating disruption efforts. Kaspersky said its security products detect the malware.

It advises users to obtain software from official or reputable sources, keep security tools enabled and avoid disabling them to download files; organisations should control third-party software use and ensure they have appropriate detection, visibility and incident-response capabilities.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline