Many individual users and organisations have been targeted by cybercriminals hiding new malware in torrents for popular films, including The Odyssey.

Kaspersky’s Global Research and Analysis Team (GReAT) found that one of the popular public archives of torrent files was compromised and was used to deliver the malicious payload.

The tech firm’s statistics show that several hundred victims have been identified in a multitude of countries, including Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries such as Spain, the Netherlands, Belgium, Germany and others.

Victims already identified include organisations operating in the enterprise, government, information and tech, consulting, retail, transportation, and agriculture sectors.

The attacks, which started in mid-August and remains ongoing, is built as a multi-stage framework composed of several elements that work together at different stages of the intrusion.

At the initial stage, the malware uses a loader capable of detecting antivirus sandboxes, which are isolated testing environments security products used to safely examine suspicious files. This allows the malware to determine whether it is being analysed and, if so, evade detection or hinder further investigation.

Once active on a victim’s device, the malware deploys additional modules that expand its capabilities. These modules allow it to establish persistence, so it remains on the system after a reboot even after it has been terminated, bypass User Account Control (UAC) to gain administrator privileges in Windows without triggering the usual warning prompt and ultimately provide the attackers with remote access to the compromised machine.

To retrieve the address of its command-and-control server, the malware uses the Solana blockchain. This gives the attackers a more resilient way to maintain control over their infrastructure and makes the campaign harder to disrupt through blocking or takedown efforts.

Konstantin Isakov, a security expert at Kaspersky GReAT, says by disguising malware as torrents for popular films, the attackers increase the likelihood that unsuspecting users will download it.

“Once launched, the multi-stage malware is designed to evade detection, establish persistence, and provide the attackers with remote access to infected devices,” Isakov explains.

He also points out, however, that users should be especially cautious with files downloaded from unofficial sources, “as even seemingly harmless entertainment content can serve as a vehicle for compromise.”

Meanwhile, Kaspersky says solution is to be cautious with downloads. It’s safer to install games and mods only from official sources or reputable websites. Unofficial sources may contain malware. Use a strong security solution on all computers and mobile devices. It will warn you about potential threats and prevent infection. And, never disable antivirus or security tools to download any files or software.

For organisations, it is better to implement clear guidelines for the use of third-party software on work devices.

Invest in threat intelligence, which involves providing InfoSec professionals with an in-depth visibility into cyberthreats targeting an organisation. It provides professionals with rich and meaningful context across the entire incident management cycle and help identify cyber risks in a timely manner.

If a company lacks cybersecurity expertise, it can adopt managed security services from a player like Kaspersky.

One problem is that most individuals and organisations today have always failed to cover malware incidents management cycle. This is because there is still a gap from threat identification to continuous protection and remediation. Some blame lack of investment in security solutions. But study of the malware by Kaspersky suggests that if precautions are not taken, the described malware is more likely to mess the non tech savvy.