🛡 MALWARE 🛡

Cibercriminales esconden nuevo malware en torrents de películas populares

🛡CyberObservatorio
Cibercriminales esconden nuevo malware en torrents de películas populares
Idioma

Cibercriminales esconden nuevo malware en torrents de películas populares

Fuente: Dark Reading

**Una Nueva Amenaza Cibernética: Campaña de Malware Disfrazada de Torrents**

En un mundo cada vez más digitalizado, la ciberseguridad se ha convertido en una preocupación esencial tanto para usuarios individuales como para organizaciones. En este contexto, el equipo de Investigación y Análisis Global de Kaspersky (GReAT) ha revelado una avanzada campaña de malware de múltiples etapas que tiene como objetivo a una amplia variedad de víctimas, desde usuarios comunes hasta instituciones gubernamentales y corporaciones. Esta situación es alarmante, ya que pone de manifiesto la vulnerabilidad inherente a la descarga de contenido aparentemente inofensivo, como películas populares, que puede enmascarar amenazas serias.

Desde mediados de agosto de 2026, se ha detectado esta campaña activa, la cual ha conseguido infectar a varios cientos de usuarios en países tan diversos como Rusia, Turquía, Japón, Kenia, Uganda y Colombia, así como en varias naciones europeas, incluyendo España, Países Bajos, Bélgica y Alemania. Las víctimas identificadas abarcan sectores críticos como el empresarial, gubernamental, tecnológico, de consultoría, retail, transporte y agricultura, lo que resalta la amplitud del impacto de esta amenaza.

El ataque se estructura en un marco de múltiples etapas que se interconectan en diferentes fases de la intrusión. En la etapa inicial, el malware se presenta a través de un loader que tiene la capacidad de detectar entornos de pruebas de antivirus, conocidos como “sandbox”. Estos entornos son utilizados por productos de seguridad para examinar archivos sospechosos de manera segura. Al poder identificar si está siendo analizado, el malware elude la detección o limita las investigaciones subsiguientes. Una vez que el malware se activa en el dispositivo de la víctima, despliega módulos adicionales que amplían sus capacidades. Estos módulos permiten que el malware establezca persistencia, lo que significa que puede permanecer en el sistema incluso después de un reinicio, eludiendo el Control de Cuentas de Usuario (UAC) para obtener privilegios de administrador en Windows sin activar las advertencias habituales, y proporcionando a los atacantes acceso remoto a la máquina comprometida.

Un aspecto técnico notable de esta campaña es el uso de la blockchain de Solana por parte del malware para recuperar la dirección de su servidor de comando y control. Esta táctica ofrece a los atacantes una forma más resistente de mantener el control sobre su infraestructura, dificultando los esfuerzos de bloqueo o desmantelamiento de la campaña.

Konstantin Isakov, experto en seguridad de Kaspersky GReAT, destaca que "la campaña es notable por combinar un señuelo común con un diseño técnico sofisticado. Al disfrazar el malware como torrents de películas populares, los atacantes aumentan la probabilidad de que usuarios desprevenidos lo descarguen. Una vez lanzado, el malware de múltiples etapas está diseñado para eludir la detección, establecer persistencia y proporcionar acceso remoto a dispositivos infectados. Los usuarios deben ser especialmente cautelosos con los archivos descargados de fuentes no oficiales, ya que incluso el contenido de entretenimiento aparentemente inofensivo puede servir como vehículo de compromiso".

Para protegerse de esta amenaza, Kaspersky recomienda a los usuarios que sean cautelosos al realizar descargas, optando por instalar juegos y modificaciones únicamente desde fuentes oficiales o sitios web de reputación comprobada. Las fuentes no oficiales pueden contener malware que comprometa la seguridad del dispositivo.

Asimismo, es crucial utilizar soluciones de seguridad robustas, como Kaspersky Premium, en todos los dispositivos informáticos y móviles. Estas herramientas no solo alertan sobre amenazas potenciales, sino que también previenen infecciones. Además, se aconseja a los usuarios no desactivar el antivirus o las herramientas de seguridad para descargar ningún archivo o software, dado que esto puede abrir la puerta a ataques maliciosos.

Las organizaciones, por su parte, deben implementar directrices claras sobre el uso de software de terceros en los dispositivos de trabajo. Además, se recomienda adoptar soluciones integrales de la línea de productos Kaspersky Next, que ofrecen protección en tiempo real, visibilidad de amenazas y capacidades de investigación y respuesta a incidentes, adaptándose a las necesidades actuales y recursos disponibles de la empresa.

En el caso de que una empresa carezca de la experiencia necesaria en ciberseguridad, es aconsejable que adopte servicios de seguridad gestionados de Kaspersky, como la Evaluación de Compromisos, Detección y Respuesta Gestionadas, y Respuesta a Incidentes, que abarcan todo el ciclo de gestión de incidentes, desde la identificación de amenazas hasta la protección continua y la remediación.

Kaspersky ha confirmado que sus soluciones de seguridad son capaces de detectar el malware descrito en esta campaña. Para un análisis técnico completo, se puede consultar la plataforma www.Securelist.com.

Kaspersky, fundado en 1997, se ha consolidado como una empresa global de ciberseguridad y privacidad digital. Con un enfoque innovador basado en la Inmunidad Cibernética, protege tanto a consumidores como a organizaciones y gobiernos frente a amenazas cibernéticas, con más de mil millones de dispositivos protegidos hasta la fecha. La compañía se destaca en proporcionar resultados claros y proteger los ingresos, aliviando cargas de trabajo y evitando tiempos de inactividad. La profunda inteligencia sobre amenazas y experiencia en seguridad de Kaspersky se transforma constantemente en soluciones y servicios innovadores para organizaciones de todos los tamaños, desde pequeñas empresas hasta grandes corporaciones. Su confianza es respaldada por millones de individuos en todo el mundo y cerca de 200,000 organizaciones, ayudándoles a detectar amenazas de manera más temprana, responder más rápido y operar con mayor confianza, protegiendo lo que más valoran. Para más información, visite www.Kaspersky.co.za.

Cybercriminals Are Hiding New Malware in Torrents for Popular Films

Source: Dark Reading

PRESS RELEASENAIROBI, Kenya , September 21, 2026 —Kaspersky's Global Research and Analysis Team (GReAT) has uncovered a sophisticated new multi-stage campaign targeting both individual users and organisations. The campaign relies on a previously unknown malware strain distributed through torrent trackers disguised as popular films, including The Odyssey. One of the popular public archives of torrent files was compromised and was then used to deliver the malicious payload. Several hundred victims have been identified in a multitude of countries, including Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries such as Spain, the Netherlands, Belgium, Germany and others. Victims already identified include organisations operating in the enterprise, government, IT, consulting, retail, transportation, and agriculture sectors. The campaign has been active since at least mid-August and remains ongoing. The attack itself is built as a multi-stage framework composed of several elements that work together at different stages of the intrusion. At the initial stage, the malware uses a loader capable of detecting antivirus sandboxes, which are isolated testing environments security products use to safely examine suspicious files. This allows the malware to determine whether it is being analysed and, if so, evade detection or hinder further investigation. Once active on a victim’s device, the malware deploys additional modules that expand its capabilities. These modules allow it to establish persistence, so it remains on the system after a reboot even after it has been terminated, bypass User Account Control (UAC) to gain administrator privileges in Windows without triggering the usual warning prompt and ultimately provide the attackers with remote access to the compromised machine. To retrieve the address of its command-and-control server, the malware uses the Solana blockchain. This gives the attackers a more resilient way to maintain control over their infrastructure and makes the campaign harder to disrupt through blocking or takedown efforts. “The campaign is notable for combining a common lure with a sophisticated technical design. By disguising malware as torrents for popular films, the attackers increase the likelihood that unsuspecting users will download it. Once launched, the multi-stage malware is designed to evade detection, establish persistence, and provide the attackers with remote access to infected devices. Users should be especially cautious with files downloaded from unofficial sources, as even seemingly harmless entertainment content can serve as a vehicle for compromise,” says Konstantin Isakov, security expert at Kaspersky GReAT. To stay safe Kaspersky recommends that users: Be cautious with downloads. It’s safer to install games and mods only from official sources or reputable websites. Unofficial sources may contain malware. Be cautious with downloads. It’s safer to install games and mods only from official sources or reputable websites. Unofficial sources may contain malware. Use a strong security solution, such asKaspersky Premium, on all computers and mobile devices. It will warn you about potential threats and prevent infection. Use a strong security solution, such asKaspersky Premium, on all computers and mobile devices. It will warn you about potential threats and prevent infection. Never disable antivirus or security tools to download any files or software. Never disable antivirus or security tools to download any files or software. Organisations are recommended to: Implement clear guidelines for the use of third-party software on work devices. Implement clear guidelines for the use of third-party software on work devices. Use all-encompassing solutions from theKaspersky Nextproduct line that provide real-time protection, threat visibility, and the investigation and response capabilities of EPP, EDR and XDR. Depending on your current needs and available resources, you can choose the most relevant solution within this product line and easily migrate to another one if your cybersecurity requirements change. Use all-encompassing solutions from theKaspersky Nextproduct line that provide real-time protection, threat visibility, and the investigation and response capabilities of EPP, EDR and XDR. Depending on your current needs and available resources, you can choose the most relevant solution within this product line and easily migrate to another one if your cybersecurity requirements change. Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organisation. The latestKaspersky Threat Intelligencewill provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner. Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organisation. The latestKaspersky Threat Intelligencewill provide them with rich and meaningful context across the entire incident management cycle and helps them identify cyber risks in a timely manner. If your company lacks cybersecurity expertise, adopt managed security services from Kaspersky such asCompromise Assessment,Managed Detection and Response, and/orIncident Response, which cover the entire incident management cycle – from threat identification to continuous protection and remediation. If your company lacks cybersecurity expertise, adopt managed security services from Kaspersky such asCompromise Assessment,Managed Detection and Response, and/orIncident Response, which cover the entire incident management cycle – from threat identification to continuous protection and remediation. Kaspersky security solutions detect the described malware. The full technical analysis is available onwww.Securelist.com. Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date. Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support. Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at (www.Kaspersky.co.za).

Cibercriminales esconden nuevo malware en torrents de películas populares | Ciberseguridad - NarcoObservatorio