Threats · 11h ago

Kaspersky Finds Torrent Archive Feeding Cross-Sector Malware

Kaspersky GReAT says a compromised public torrent archive has been feeding a new multi-stage malware campaign since at least mid-August, with several hundred victims already identified across Russia, Türkiye, Japan, Kenya, Uganda, Colombia, and several European countries. The lure is a popular film torrent, including one disguised as The Odyssey.

The infection starts when a user downloads the fake torrent and runs the payload. From there the malware checks for sandbox analysis, adds persistence, bypasses User Account Control to gain administrator rights in Windows, and uses the Solana blockchain to fetch its command-and-control address, making the campaign harder to block or disrupt.

The exposure sits where consumer file-sharing habits meet enterprise devices: if employees can use torrents or other peer-to-peer downloads, a public archive compromise can become a cross-sector entry path that standard email-and-phishing defenses will miss.

Timeline

Sources

1 source covering this story

Part of the PlainSec briefing for 2026-09-22

Editions

Related stories