Executive Summary
In September 2026, Kaspersky's Global Research and Analysis Team uncovered a sophisticated multi-stage malware campaign targeting individuals and organizations through compromised torrent files disguised as popular films including The Odyssey. Active since mid-August 2026, the attack affected hundreds of victims across Russia, Turkey, Japan, Kenya, Uganda, Colombia, and several European countries. The malware employs advanced evasion techniques including sandbox detection, UAC bypass, and uses the Solana blockchain for command-and-control infrastructure resilience, ultimately providing attackers with persistent remote access to compromised systems.
This incident highlights the evolving sophistication of malware distribution campaigns that exploit legitimate entertainment content as attack vectors. The combination of social engineering through popular media, advanced technical evasion capabilities, and blockchain-based infrastructure represents a concerning trend in cybercrime operations that traditional security measures may struggle to detect and mitigate effectively.
Why This Matters Now
This campaign demonstrates how cybercriminals are increasingly weaponizing entertainment content and leveraging blockchain technology for infrastructure resilience, making traditional takedown efforts ineffective while expanding their reach across multiple sectors and geographic regions.
Attack Path Analysis
Attackers compromised a torrent tracker to distribute multi-stage malware disguised as popular films, establishing persistence through sandbox evasion and UAC bypass. The malware used Solana blockchain for C2 communication resilience while providing remote access capabilities for data theft and system control across multiple countries and sectors.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers compromised a popular torrent tracker and distributed multi-stage malware disguised as torrents for films like 'The Odyssey', targeting users downloading from unofficial sources
MITRE ATT&CK® Techniques
Spearphishing Attachment
Malicious File
Virtualization/Sandbox Evasion
Bypass User Account Control
Registry Run Keys / Startup Folder
Multi-hop Proxy
Dead Drop Resolver
Ingress Tool Transfer
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Bespoke and Custom Software Development
Control ID: 6.2.1
NYDFS 23 NYCRR 500 – Information Security Program
Control ID: 500.02(b)
DORA – ICT Risk Management Framework
Control ID: Article 8
CISA ZTMM 2.0 – Application Security
Control ID: Applications and Workloads
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO 27001 – Controls Against Malware
Control ID: A.12.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Entertainment/Movie Production
High risk from torrent-based malware distribution targeting popular films, compromising content distribution systems and enabling remote access to production networks.
Government Administration
Significant exposure as identified victims include government organizations, facing multi-stage malware with persistence capabilities and blockchain-based command-and-control infrastructure.
Information Technology/IT
Critical risk from sophisticated malware targeting IT consulting firms, bypassing security controls through torrent vectors and establishing persistent remote access.
Retail Industry
Substantial threat as retail organizations are confirmed victims of this campaign, vulnerable to data exfiltration through compromised torrent downloads.
Sources
- Cybercriminals Are Hiding New Malware in Torrents for Popular Filmshttps://www.darkreading.com/cyberattacks-data-breaches/cybercriminals-hiding-new-malware-torrents-popular-filmsVerified
- Kaspersky GReAT Analysis of Multi-Stage Torrent Malware Campaignhttps://www.securelist.comVerified
- CISA Cybersecurity Advisory on Torrent-Based Malware Distributionhttps://www.cisa.gov/news-events/cybersecurity-advisoriesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this multi-stage malware campaign by limiting lateral movement paths and reducing the attack surface across compromised enterprise networks. The segmentation and egress controls could have minimized the blast radius from initial torrent-based compromise to widespread multi-sector impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial malware execution would likely still occur on endpoint systems, but CNSF visibility would have provided earlier detection of anomalous network behavior patterns from compromised workloads attempting to establish external connections.
Control: Zero Trust Segmentation
Mitigation: Local privilege escalation may have succeeded, but zero trust controls would likely have limited the scope of elevated access to segmented workload boundaries rather than broad administrative privileges across network resources.
Control: East-West Traffic Security
Mitigation: Network discovery and lateral movement attempts would likely have been significantly constrained by microsegmentation policies, limiting attacker visibility to adjacent workloads and reducing reachability to critical enterprise systems.
Control: Multicloud Visibility & Control
Mitigation: Blockchain-based C2 communication may have been established, but multicloud visibility controls would likely have detected and logged the anomalous cryptocurrency network traffic patterns for security analysis and potential blocking.
Control: Egress Security & Policy Enforcement
Mitigation: Data exfiltration attempts would likely have been constrained by egress filtering policies, reducing the volume and scope of sensitive information that could be transmitted to external attacker infrastructure.
While some organizational compromise may have remained, the overall campaign impact would likely have been significantly reduced through constrained lateral movement and limited data exfiltration capabilities across affected enterprise networks.
Impact at a Glance
Affected Business Functions
- IT Infrastructure Management
- Data Security Operations
- Remote Access Systems
- Enterprise Network Administration
Estimated downtime: 7 days
Estimated loss: $250,000
Potential compromise of enterprise credentials, internal network access, and sensitive business data across multiple sectors including government, IT consulting, retail, transportation, and agriculture organizations in affected countries
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Cloud Firewall (ACF) with URL filtering to block access to known malicious torrent sites and prevent initial malware downloads from unofficial sources
- • Implement Egress Security & Policy Enforcement to detect and block suspicious outbound communications to Solana blockchain infrastructure used for C2 retrieval
- • Enable Zero Trust Segmentation with least privilege policies to prevent UAC bypass malware from accessing critical enterprise resources and lateral movement
- • Deploy Threat Detection & Anomaly Response capabilities to identify sandbox evasion techniques and multi-stage malware deployment patterns
- • Utilize Multicloud Visibility & Control to monitor for suspicious automation and repeated malformed requests indicative of remote access tool usage across hybrid environments



