Cybercriminals Are Hiding New Malware in Torrents for Popular Films

Sophisticated Malware Campaign Targets Users with Torrents for Popular Films

A highly sophisticated malware campaign has been uncovered by Kaspersky’s Global Research and Analysis Team (GReAT), targeting both individual users and organisations worldwide. The campaign, which remains ongoing, relies on a previously unknown malware strain distributed through torrent trackers disguised as popular films, including “The Odyssey”. This insidious tactic has already victimized hundreds of individuals and organisations across multiple countries, with notable cases in Africa, Russia, Türkiye, Japan, and several European nations.

At its core, the attack is built around a multi-stage framework composed of several elements that work together to infiltrate and compromise devices. The malware uses a loader capable of detecting antivirus sandboxes, allowing it to evade detection or hinder further investigation if it senses being analysed. Once active on a victim’s device, the malware deploys additional modules that expand its capabilities, including establishing persistence, bypassing User Account Control (UAC), and providing attackers with remote access to compromised machines.

What sets this campaign apart is its use of the Solana blockchain to retrieve the address of its command-and-control server. This gives attackers a more resilient way to maintain control over their infrastructure, making it harder for security teams to disrupt through blocking or takedown efforts. “The campaign combines a common lure with sophisticated technical design,” warns Konstantin Isakov, a Kaspersky GReAT security expert. “Users should be especially cautious with files downloaded from unofficial sources, as even seemingly harmless entertainment content can serve as a vehicle for compromise.”

As the campaign remains active and ongoing, users are advised to exercise extreme caution when downloading files from unofficial sources. This includes torrent trackers that may contain malicious payloads disguised as popular films or other entertainment content. Kaspersky recommends using strong security solutions on all devices, including those provided by their Premium product line, which can warn of potential threats and prevent infection. Organisations are also advised to implement clear guidelines for third-party software use on work devices, utilise comprehensive security solutions from the Kaspersky Next product line, and provide their InfoSec professionals with timely threat intelligence.

Ultimately, this campaign serves as a stark reminder that even seemingly harmless content can pose significant risks. As users continue to engage with digital entertainment, it is essential to remain vigilant and avoid downloading files from unofficial sources, opting instead for official channels or reputable websites. By staying informed and taking proactive measures, individuals and organisations can mitigate the risk of falling victim to this insidious malware campaign.


Source: Dark Reading — 2026-09-21