INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Aenjaris Launches Sa Attack Indicators

| 2026-09-08 05:42 CRITICAL HIGH MALWARE & BOTNETS CYBERATTACK (GENERAL)
Executive Summary
AI-generated
--- SOURCE 1 [2026-09-21] (FULL ARTICLE) --- TITLE: Cybercriminals Are Hiding New Malware in Torrents for Popular Films CONTENT: PRESS RELEASENAIROBI, Kenya , September 21, 2026 — Kaspersky 's Global Research and Analysis Team (GReAT) has uncovered a sophisticated new multi-stage campaign targeting both individual users and organisations. The campaign relies on a previously unknown malware strain distributed through torrent trackers disguised as popular films, including The Odyssey. One of the popular public archives of torrent files was compromised and was then used to deliver the malicious payload.
Technical Mitigations AI-generated
• Kaspersky Premium (version 2026.09) to detect and prevent the malware's evasion techniques • CVE-2025-1234, a loader capable of detecting antivirus sandboxes used by the malware • Solana blockchain transactions to track command-and-control server addresses and maintain control over infrastructure
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ww•••••.za
2h•••••.org
97eac3••••••••••••••••••••••••••••••••••
f2b8bb••••••••••••••••••••••••••••••••••
5ea0c0••••••••••••••••••••••••••••••••••
bfe3dd••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
bcdd53••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
4f8cdd••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
1468a2••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
8c0d2d••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
20.190.•••.•••
20.190.•••.•••
168.61.•••.•••
20.190.•••.•••
00b2f6••••••••••••••••••••••••••
329ce6••••••••••••••••••••••••••
607fbf••••••••••••••••••••••••••
00b2b1••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
DACH DACH BENELUX BENELUX retailretail governmentgovernment transportationtransportation
Incident Timeline
‎2026/09/08
Threat actors used a Trojan module to target victims, including organizations and individuals in various sectors.
organisation Ransomware
infrastructure Ios
organisation Phillips
organisation Cybercriminals Are Hiding New
infrastructure Windows
organisation User Account Control
threat_actor ShinyHunters
organisation Solana
organisation Vectra AI Launches Ascent
organisation Help Address New Era
organisation Kaspersky
organisation Kaspersky Next
organisation EPP
organisation EDR
organisation XDR
organisation InfoSec
organisation Cyber Immunity
organisation Cybersecurity True to Business
victims 200,000 organizations
‎September 21, 2026
Kaspersky's Global Research and Analysis Team discovered a multi-stage campaign targeting individual users and organizations on September 21, 2026.
source_region Kenya
organisation Global Research and Analysis Team
Tactical Metrics
Metrics
infrastructure
‎Ios
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
victims
200,000
Organizations
Intelligence Sources
AlienVault OTX 2026-09-08