Cybersecurity

Kaspersky Uncovers a Multistage Campaign Hiding Malware in Torrent Files for Popular Movies

Kaspersky detected a campaign that began in mid-August 2026 and exploits movie torrent files, including The Odyssey, to spread malware capable of stealth, persistence, and bypassing UAC, while using the Solana blockchain to discover command-and-control servers.

2026-09-18
3 min read
1 views
certi.news
Kaspersky Uncovers a Multistage Campaign Hiding Malware in Torrent Files for Popular Movies

Kaspersky’s Global Research and Analysis Team (GReAT) detected a multistage cyber campaign targeting individuals and organizations by hiding previously unknown malware inside torrent files for popular movies, including the new The Odyssey. The campaign’s activity began in mid-August 2026 and is still ongoing, according to the company.

Kaspersky identified hundreds of victims in Russia, Turkey, Japan, Kenya, Uganda, and Colombia, as well as Spain, the Netherlands, Belgium, and Germany. The affected entities included organizations in the business, government, information technology, consulting, retail, transportation, and agriculture sectors, expanding the scope of the threat beyond individual entertainment users.

How does the campaign work?

The attackers exploited a breach of a public archive site used to store torrent files, then published the malicious files to reach users. The infection begins with a downloader capable of detecting isolated testing environments used by security software to analyze suspicious files. When analysis is detected, the tool can take steps to hide itself or obstruct the investigation.

After activation on the victim’s device, the malware deploys additional modules that help it maintain a presence after the device is restarted or the malicious process is terminated. It also includes capabilities to bypass the User Account Control (UAC) feature in Windows, with the aim of obtaining administrator privileges without displaying the usual warning message, potentially allowing attackers to access the device remotely.

Using Solana in the command-and-control infrastructure

The campaign relies on the Solana blockchain to obtain the address of the command-and-control (C2) server. This approach gives the attackers’ infrastructure greater flexibility and makes disrupting the campaign more difficult compared with relying on servers that can be blocked or dismantled directly.

Why does this matter?

The campaign demonstrates that entertainment files circulated through unofficial sources can become an entry point into corporate environments, particularly when the malware combines analysis-environment detection, persistence, privilege escalation, and a flexible mechanism for accessing control servers. The practical impact is not limited to preventing the download of suspicious files; organizations also need to regulate the use of external software, monitor endpoints, and investigate unusual behavior.

Kaspersky recommended downloading files from official or trusted sources, not disabling security software, and using effective security solutions. For organizations, it called for establishing policies governing the use of external software and leveraging endpoint protection and extended detection and response capabilities, alongside threat intelligence and penetration-testing assessment and incident-response services when specialized expertise is lacking.

Konstantin Isakov, a cybersecurity expert on Kaspersky’s GReAT team, said that the campaign combines the lure of movie files with an advanced technical infrastructure. The company confirmed that its solutions detected the malware used, while the full technical analysis is available through Securelist.com. The source does not specify the name of the malware family or provide a detailed number of affected organizations; these points require review of the original technical analysis.

News source
AITnews Arabic
Open original source ↗
c
Author

certi.news

In the same category

You may also like

View all news