The latest campaign
Kaspersky's Global Research and Analysis Team has uncovered a new malware operation running since at least mid-August. Attackers compromised a public torrent archive and seeded files for popular films, including The Odyssey. Several hundred victims have already been recorded among individuals and organisations in Spain, the Netherlands, Belgium, Germany and other European countries, plus Russia, Tรผrkiye, Japan, Kenya, Uganda and Colombia.
How the malware works
The attack uses a loader that checks for antivirus sandboxes before deploying further modules. These modules establish persistence, bypass User Account Control to gain admin rights, and open remote access. Command-and-control addresses are fetched via the Solana blockchain, making takedowns harder.
โThe campaign is notable for combining a common lure with a sophisticated technical design. By disguising malware as torrents for popular films, the attackers increase the likelihood that unsuspecting users will download it. Once launched, the multi-stage malware is designed to evade detection, establish persistence, and provide the attackers with remote access to infected devices. Users should be especially cautious with files downloaded from unofficial sources, as even seemingly harmless entertainment content can serve as a vehicle for compromise,โ โ says Konstantin Isakov, security expert at Kaspersky GReAT.
Who it affects and what to do
Sectors already hit include enterprise, government, IT, consulting, retail, transportation and agriculture. Kaspersky detects the malware and urges users to stick to official sources, keep security tools enabled and avoid disabling protection to download anything. Organisations should set clear rules on third-party software and consider layered defences.
This comes the same day as our coverage of another Kaspersky discovery: Updated MacSync Malware Now Targets macOS Credentials and Crypto. For broader protection options, see our VPN comparison.









