Skip to content

Security1 publisher2 min readPublished

A compromised public torrent archive has been serving malware to government and enterprise PCs since mid-August

Kaspersky says a previously unknown multi-stage loader has spread since mid-August through a compromised public torrent archive. It reaches its command server through the Solana blockchain. Victims include government and transport organisations.

The Watch · Security desk

Illustration accompanying A compromised public torrent archive has been serving malware to government and enterprise PCs since mid-August

What happened

  • Kaspersky's GReAT team said one of the popular public torrent archives was compromised and then used to deliver a previously unknown malware strain disguised as torrents for films including The Odyssey.
  • Several hundred victims have been identified in Russia, Turkiye, Japan, Kenya, Uganda and Colombia, plus European countries including Spain, the Netherlands, Belgium and Germany.
  • The organisations among them run in the enterprise, government, IT, consulting, retail, transportation and agriculture sectors.
  • Distribution started by mid-August and the campaign was still running when Kaspersky published the account on 21 September.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A film download on work hardware hands an outside operator administrator rights and remote access on a machine inside a government, transport or agriculture network. The control that failed is software policy on the endpoint.
  • capability Because the command server address comes off a public blockchain, domain blocklists and server seizures leave the channel intact and detection has to happen on the host.
  • constraint The public account gives a start date and a sector list, so any retrospective hunt has to be built on behavioural telemetry.
  • decision There is no specific site to block, so the choice moves to the application layer: whether torrent clients are allowed to run on managed endpoints at all.

The delivery path is the point here, not acceptable use. Kaspersky's account says one of the popular public archives of torrent files was itself compromised, then used to deliver the payload [1]. Someone who had pulled files from that archive for years would have seen the archive they expected, with a listing for The Odyssey [1][2].

The first stage is a loader that checks whether it is running in an antivirus sandbox, so it can tell when it is under analysis and either evade detection or frustrate the investigation [6]. When it proceeds, later modules add persistence that survives reboot and termination, a bypass of User Account Control that takes administrator rights without the usual Windows prompt, and remote access for the operator [7].

For its command-and-control address, the malware queries the Solana blockchain [8]. Kaspersky says the design gives the attackers a more resilient way to hold their infrastructure and makes the campaign harder to disrupt through blocking or takedown efforts [8].

Counting from about 15 August to the 21 September disclosure gives at least 37 days, roughly five weeks of distribution before any public notice [13]. Kaspersky puts several hundred victims in that window [3], across ten named countries plus others it did not list [14], in seven named sectors [15].

Dark Reading carried the account as a Kaspersky press release, datelined Nairobi, 21 September 2026 [10]. It does not name the compromised archive or publish hashes or command server addresses. Kaspersky says the full technical analysis is on Securelist and that its own products detect the malware [12][11]. Its advice to organisations is to set clear guidelines for the use of third-party software on work devices [16].

"Users should be especially cautious with files downloaded from unofficial sources, as even seemingly harmless entertainment content can serve as a vehicle for compromise," said Konstantin Isakov, a security expert at Kaspersky GReAT [9].

A team working from that date range has behaviour to go on: processes spawned by torrent clients and media players since mid-August [5], UAC bypass attempts on workstations [7], and blockchain queries from hosts with no business reason to make one [8].

What to watch

  • Whether the Securelist technical write-up names the compromised archive and publishes hashes and the Solana lookup logic.
  • Whether any other vendor or CERT corroborates the several-hundred victim count and the sector list.
  • Whether the archive operator confirms the compromise and says when it was cleaned, since Kaspersky calls the campaign ongoing.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories