Threats & Adversaries · Supply Chain

Kaspersky Finds Torrent Archive Feeding Cross-Sector Malware

Kaspersky GReAT says a compromised public torrent archive has been feeding a new multi-stage malware campaign since at least mid-August, with several hundred victims already identified across Russia, Türkiye, Japan, Kenya, Uganda, Colombia, and several European countries. The lure is a popular film torrent, including one disguised as The Odyssey.

The infection starts when a user downloads the fake torrent and runs the payload. From there the malware checks for sandbox analysis, adds persistence, bypasses User Account Control to gain administrator rights in Windows, and uses the Solana blockchain to fetch its command-and-control address, making the campaign harder to block or disrupt.

The exposure sits where consumer file-sharing habits meet enterprise devices: if employees can use torrents or other peer-to-peer downloads, a public archive compromise can become a cross-sector entry path that standard email-and-phishing defenses will miss.

1 source · 12h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-09-22

Every edition of this story: Kaspersky Finds Torrent Archive Feeding Cross-Sector Malware

More from today