Kaspersky’s Global Research and Analysis Team (GReAT) has identified an advanced, multi-stage cyber campaign targeting both individual users and organizations. The attackers hide previously unknown malware inside torrent files for popular films, including the new movie “The Odyssey.”

Researchers have identified hundreds of victims across several countries, including Russia, Turkey, Japan, Kenya, Uganda, Colombia, and European nations such as Spain, the Netherlands, Belgium, and Germany. The victims include organizations in business, government, IT, consulting, retail, transportation, and agriculture sectors.

According to Kaspersky, the campaign began in mid-August 2026 and remains active. The attackers exploited a breach of a public archive site used for storing torrent files to distribute the malware and reach users.

A Multi-Stage Attack Designed to Evade Detection

The attackers designed the campaign as a multi-stage framework with components that work together to carry out intrusions and expand control over infected devices.

The process begins with a malicious loader capable of detecting isolated test environments used by antivirus programs to scan suspicious files. This helps the malware determine whether it is being analyzed and take steps to hide, evade detection, or obstruct later investigations.

Once activated on a victim’s device, the malware can deploy additional modules that allow it to maintain a presence on the system even after a reboot or termination of the malicious process.

Its capabilities include bypassing the User Account Control (UAC) feature in Windows to gain administrator privileges without displaying the usual warning prompt, giving attackers remote access to infected devices.

Solana Blockchain Used to Secure Communication with Attackers

The campaign relies on the Solana blockchain to obtain the command-and-control (C2) server address used by attackers to manage the malware and communicate with infected devices.

This method helps attackers enhance the resilience of their infrastructure and makes it harder to disrupt the campaign by blocking or dismantling servers.

Kaspersky: Entertainment Files Can Become an Attack Vector

Konstantin Isakov, a cybersecurity expert in Kaspersky’s Global Research and Analysis Team, said:

“This malicious campaign combines a common lure with advanced technical infrastructure. By disguising malware as torrent files for popular films, attackers increase the likelihood that careless users will download them.

Once launched, this multi-stage malware can evade detection, ensure persistence on the system, and give attackers remote access to infected devices.

Therefore, users should be cautious when downloading files from unofficial sources; even seemingly harmless entertainment content can become a means to compromise systems.”

Kaspersky Recommendations for User Protection

Kaspersky advises users to follow a set of measures to reduce the risk of malware infection, including:

  • Download games, mods, and files from official sources or trusted websites, and avoid unofficial sources that may contain malware.
  • Use effective security solutions on computers and mobile devices, such as Kaspersky Premium, to detect potential threats, warn about them, and prevent infection.
  • Do not disable antivirus programs or security tools for the purpose of downloading files or installing software.

Recommendations for Enterprise Protection

The company also recommended that organizations take measures to enhance the security of their devices and networks, including:

  • Establish clear guidelines for regulating the use of third-party software on company devices.
  • Use comprehensive security solutions, such as the Kaspersky Next product line, which provides continuous protection and comprehensive visibility of threats, along with investigation and response capabilities within Endpoint Protection Platform (EPP), Endpoint Detection and Response (EDR), and Extended Detection and Response (XDR) solutions. The line allows choosing the level of protection according to the organization’s needs and resources, with the ability to change it as cybersecurity requirements evolve.
  • Provide information security teams with in-depth visibility of cyber threats by leveraging the Kaspersky Threat Intelligence platform, which offers contextual information to support incident management and timely risk identification.
  • Use managed security services when specialized expertise is lacking within the organization, including Compromise Assessment, Managed Detection and Response (MDR), and Incident Response services, which support incident management stages from threat identification to remediation and continuous protection.

Kaspersky confirmed that its security solutions detected the malware used in the campaign, noting that the full technical analysis is available on Securelist.com.

By Ryan

Leave a Reply

Your email address will not be published. Required fields are marked *