Home » Cybercriminals hiding new malware in movie torrents

Cybercriminals hiding new malware in movie torrents

Kaspersky’s Global Research and Analysis Team (GReAT) has uncovered a sophisticated new multi-stage campaign targeting both individual users and organisations. The campaign relies on a previously unknown malware strain distributed through torrent trackers disguised as popular films, including The Odyssey. One popular public torrent archive was compromised and then used to deliver the malicious payload.

Several hundred victims have been identified in multiple countries, including Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries such as Spain, the Netherlands, Belgium, Germany, and others. Victims already identified include organisations operating in the enterprise, government, IT, consulting, retail, transportation, and agriculture sectors. The campaign has been active since at least mid-August and remains ongoing.

The attack uses a multi-stage framework composed of several elements that work together at different stages of the intrusion. At the initial stage, the malware uses a loader capable of detecting antivirus sandboxes, which are isolated testing environments security products use to safely examine suspicious files. This allows the malware to determine whether it is being analysed and, if so, evade detection or hinder further investigation. Once active on a victim’s device, the malware deploys additional modules that expand its capabilities. These modules allow it to establish persistence, so it remains on the system after a reboot even after it has been terminated, bypass User Account Control (UAC) to gain administrator privileges in Windows without triggering the usual warning prompt and ultimately provide the attackers with remote access to the compromised machine.

To retrieve the address of its command-and-control server, the malware uses the Solana blockchain. This gives the attackers a more resilient way to maintain control over their infrastructure and makes the campaign harder to disrupt through blocking or takedown efforts.

“The campaign is notable for combining a common lure with a sophisticated technical design. By disguising malware as torrents for popular films, the attackers increase the likelihood that unsuspecting users will download it. Once launched, the multi-stage malware is designed to evade detection, establish persistence, and provide the attackers with remote access to infected devices. Users should be especially cautious with files downloaded from unofficial sources, as even seemingly harmless entertainment content can serve as a vehicle for compromise,” says Konstantin Isakov, security expert at Kaspersky GReAT.

To stay safe Kaspersky recommends that users:

  • Be cautious with downloads. It’s safer to install games and mods only from official sources or reputable websites. Unofficial sources may contain malware.
  • Use a strong security solution, such as Kaspersky Premium, on all computers and mobile devices. It will warn you about potential threats and prevent infection.
  • Never disable antivirus or security tools to download any files or software.

 

Have your say!

0 0

Lost Password

Please enter your username or email address. You will receive a link to create a new password via email.