A sophisticated multi-stage malware campaign has been uncovered, targeting individual users and organisations globally. The campaign, active since mid-August, uses a previously unknown malware strain distributed through torrent trackers disguised as popular films. One compromised public archive of torrent files was used to deliver the malicious payload. Several hundred victims have been identified in multiple countries, including Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as several European countries.
The malware campaign relies on a common lure, disguising itself as popular films, including The Odyssey, to increase the likelihood of unsuspecting users downloading it. Once launched, the multi-stage malware is designed to evade detection, establish persistence, and provide attackers with remote access to infected devices. The attack is built as a multi-stage framework composed of several elements that work together at different stages of the intrusion. This allows the malware to determine whether it is being analysed and, if so, evade detection or hinder further investigation.
The malware uses a loader capable of detecting antivirus sandboxes, isolated testing environments security products use to safely examine suspicious files. Once active on a victim's device, the malware deploys additional modules that expand its capabilities. These modules allow it to establish persistence, so it remains on the system after a reboot, even after it has been terminated. The malware also bypasses User Account Control to gain administrator privileges in Windows without triggering the usual warning prompt.
The campaign has been active since at least mid-August and remains ongoing. Victims already identified include organisations operating in the enterprise, government, IT, consulting, retail, transportation, and agriculture sectors. To retrieve the address of its command-and-control server, the malware uses the Solana blockchain, giving attackers a more resilient way to maintain control over their infrastructure.
Konstantin Isakov, a security expert at Kaspersky, notes that the campaign combines a common lure with a sophisticated technical design. By disguising malware as torrents for popular films, attackers increase the likelihood that unsuspecting users will download it. Users are advised to be cautious with files downloaded from unofficial sources, as even seemingly harmless entertainment content can serve as a vehicle for compromise.
To stay safe, Kaspersky recommends that users be cautious with downloads and only install games and mods from official sources or reputable websites. A strong security solution should be used on all computers and mobile devices to warn about potential threats and prevent infection. Organisations are recommended to implement clear guidelines for the use of third-party software on work devices and provide InfoSec professionals with in-depth visibility into cyberthreats targeting their organisation.
The Kaspersky Global Research and Analysis Team has identified several hundred victims in multiple countries, highlighting the global nature of the threat. The team continues to monitor the situation and provide recommendations for users and organisations to stay safe. By taking precautions and being aware of the risks, individuals and organisations can reduce their vulnerability to malware attacks.
Key points
- Hundreds of victims identified in multiple countries, including Kenya and Uganda
- Malware campaign uses previously unknown strain distributed through torrent trackers disguised as popular films
- Users and organisations advised to be cautious with downloads and take precautions to stay safe