Cybercriminals Are Hiding New Malware in Torrents for Popular Films
Kaspersky researchers have uncovered a sophisticated malware campaign distributing a multi-stage threat disguised as torrents of popular films. The campaign, active since mid-August, targets both individual users and organizations across multiple countries, including Kenya, Uganda, Russia, and several European nations. The malware uses a blockchain-based command-and-control system for resilience and employs techniques to evade detection, establish persistence, and gain remote access to compromised devices. Kaspersky recommends caution with downloads, implementing clear third-party software guidelines, and utilizing their comprehensive security solutions and managed services.
Kaspersky's Global Research and Analysis Team (GReAT) has uncovered a sophisticated malware campaign distributing a multi-stage threat disguised as torrents of popular films. The campaign, active since at least mid-August, targets both individual users and organizations across multiple countries, including Kenya, Uganda, Russia, and several European nations such as Spain, the Netherlands, Belgium, and Germany. The malware utilizes a blockchain-based command-and-control system, leveraging the Solana blockchain, to enhance its resilience and make takedown efforts more difficult.
At the core of the attack is a multi-stage framework designed to evade detection and maintain persistent access to compromised systems. The malware initially employs a loader capable of detecting antivirus sandboxes, allowing it to determine if it’s being analyzed and, if so, evade detection or hinder further investigation. Once active on a victim’s device, the malware deploys additional modules that expand its capabilities, including establishing persistence even after reboots and bypassing User Account Control (UAC) to gain administrator privileges without triggering a warning prompt.
The campaign relies on a previously unknown malware strain distributed through torrent trackers. One of the popular public archives of torrent files was compromised and then used to deliver the malicious payload. Several hundred victims have been identified in a multitude of countries.
Organizations operating in various sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture, have been affected. Kaspersky security solutions detect the described malware. The full technical analysis is available on www.Securelist.com.
Kaspersky recommends that users:
- Be cautious with downloads. It’s safer to install games and mods only from official sources or reputable websites. Unofficial sources may contain malware.
- Never disable antivirus or security tools to download any files or software.
Organizations are recommended to:
- Implement clear guidelines for the use of third-party software on work devices.
- Use all-encompassing solutions from the Kaspersky Next product line that provide real-time protection, threat visibility, and the investigation and response capabilities of EPP, EDR and XDR. Depending on your current needs and available resources, you can choose the most relevant solution within this product line and easily migrate to another one if your cybersecurity requirements change.
- Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organization. The latest Kaspersky Threat Intelligence will provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner.
- If your company lacks cybersecurity expertise, adopt managed security services from Kaspersky such as Compromise Assessment, Managed Detection and Response, and/or Incident Response, which cover the entire incident management cycle – from threat identification to continuous protection and remediation.
