News

Kaspersky: Cybercriminals are hiding new malware in torrents for popular films, including The Odyssey

Kaspersky’s Global Research and Analysis Team (GReAT) has uncovered a sophisticated new multi-stage campaign targeting both individual users and organisations.

The campaign relies on a previously unknown malware strain distributed through torrent trackers disguised as popular films, including The Odyssey.

One of the popular public archives of torrent files was compromised and was then used to deliver the malicious payload. Several hundred victims have been identified in a multitude of countries, including Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries such as Spain, the Netherlands, Belgium, Germany and others. Victims already identified include organisations operating in the enterprise, government, IT, consulting, retail, transportation, and agriculture sectors.

The campaign has been active since at least mid-August and remains ongoing.

The attack itself is built as a multi-stage framework composed of several elements that work together at different stages of the intrusion. At the initial stage, the malware uses a loader capable of detecting antivirus sandboxes, which are isolated testing environments security products use to safely examine suspicious files.

This allows the malware to determine whether it is being analysed and, if so, evade detection or hinder further investigation. Once active on a victim’s device, the malware deploys additional modules that expand its capabilities.

These modules allow it to establish persistence, so it remains on the system after a reboot even after it has been terminated, bypass User Account Control (UAC) to gain administrator privileges in Windows without triggering the usual warning prompt and ultimately provide the attackers with remote access to the compromised machine.

To retrieve the address of its command-and-control server, the malware uses the Solana blockchain. This gives the attackers a more resilient way to maintain control over their infrastructure and makes the campaign harder to disrupt through blocking or takedown efforts.

“The campaign is notable for combining a common lure with a sophisticated technical design. By disguising malware as torrents for popular films, the attackers increase the likelihood that unsuspecting users will download it.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

To Top