by Thinus Ferreira
The antivirus and security solutions company Kaspersky now warns that what looks to users like downloaded film torrents - for instance, The Odyssey - now hide malware, with a recent case that hit victims in countries across Europe, Russia, Japan, and even Uganda in Africa.
Kaspersky's global research and analysis team discovered a malware strain distributed through torrent trackers, disguised as popular films, including The Odyssey.
According to Kaspersky, a popular public archive of torrent files was compromised and then used to recently deliver a malicious payload - one that got downloaded by several hundred victims.
These victims downloaded what they thought was a torrent of The Odyssey since mid-August, and affected people and businesses from Russia, Türkiye, Japan, Kenya and Uganda, to Colombia, and several European countries such as Spain, the Netherlands, Belgium and Germany.
Since people download torrents at work, they have infected organisations ranging from companies in the enterprise, IT and consulting sectors, to governments, retail, transportation, and agriculture industries.
Kaspersky explains that the malware used a loader capable of detecting antivirus sandboxes.
Quite strikingly, the malware has the ability to determine whether it is being analysed and, if so, evade detection or hinder further investigation.
"Once active on a victim's device, the malware deploys additional modules that expand its capabilities," Kaspersky says.
"These modules allow it to establish persistence, so it remains on the system after a reboot even after it has been terminated, bypass User Account Control (UAC) to gain administrator privileges in Windows without triggering the usual warning prompt and ultimately provide the attackers with remote access to the compromised machine."
Konstantin Isakov, a Kaspersky security expert, says "The campaign is notable for combining a common lure with a sophisticated technical design".
"By disguising malware as torrents for popular films, the attackers increase the likelihood that unsuspecting users will download it."
"Once launched, the multi-stage malware is designed to evade detection, establish persistence, and provide the attackers with remote access to infected devices. Users should be especially cautious with files downloaded from unofficial sources, as even seemingly harmless entertainment content can serve as a vehicle for compromise."





