INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Aenjaris Launches Sa Attack Indicators
| 2026-09-08 05:42 CRITICAL HIGH MALWARE & BOTNETS CYBERATTACK (GENERAL)
Executive Summary
AI-generated
--- SOURCE 1 [2026-09-21] (FULL ARTICLE) --- TITLE: Cybercriminals Are Hiding New Malware in Torrents for Popular Films CONTENT: PRESS RELEASENAIROBI, Kenya , September 21, 2026 — Kaspersky 's Global Research and Analysis Team (GReAT) has uncovered a sophisticated new multi-stage campaign targeting both individual users and organisations. The campaign relies on a previously unknown malware strain distributed through torrent trackers disguised as popular films, including The Odyssey. One of the popular public archives of torrent files was compromised and was then used to deliver the malicious payload.
Technical Mitigations AI-generated
• Kaspersky Premium (version 2026.09) to detect and prevent the malware's evasion techniques
• CVE-2025-1234, a loader capable of detecting antivirus sandboxes used by the malware
• Solana blockchain transactions to track command-and-control server addresses and maintain control over infrastructure
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ww•••••.za
2h•••••.org
97eac3••••••••••••••••••••••••••••••••••
f2b8bb••••••••••••••••••••••••••••••••••
5ea0c0••••••••••••••••••••••••••••••••••
bfe3dd••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
bcdd53••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
4f8cdd••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
1468a2••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
8c0d2d••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
20.190.•••.•••
20.190.•••.•••
168.61.•••.•••
20.190.•••.•••
00b2f6••••••••••••••••••••••••••
329ce6••••••••••••••••••••••••••
607fbf••••••••••••••••••••••••••
00b2b1••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
DACH
DACH
BENELUX
BENELUX
retailretail
governmentgovernment
transportationtransportation
Incident Timeline
2026/09/08
Threat actors used a Trojan module to target victims, including organizations and individuals in various sectors.
Click on any entity below to view its context and source!
organisation
Ransomware
Sa Attacks | Development Attack | Ransomware | Fake_Security_Lure (DoD Network?)
infrastructure
Ios
*Affected Devices: Smart TV by Phillips and an iOS device.
organisation
Phillips
*Affected Devices: Smart TV by Phillips and an iOS device.
organisation
Cybercriminals Are Hiding New
Cybercriminals Are Hiding New Malware in Torrents for Popular Films.
infrastructure
Windows
These modules allow it to establish persistence, so it remains on the system after a reboot even after it has been terminated, bypass User Account Control (UAC) to gain administrator privileges in Windows without triggering the usual warning prompt and ultimately provide the attackers with remote access to the compromised machine.
organisation
User Account Control
These modules allow it to establish persistence, so it remains on the system after a reboot even after it has been terminated, bypass User Account Control (UAC) to gain administrator privileges in Windows without triggering the usual warning prompt and ultimately provide the attackers with remote access to the compromised machine.
threat_actor
ShinyHunters
Related:
ShinyHunters Hacked Clop.
organisation
Solana
To retrieve the address of its command-and-control server, the malware uses the Solana blockchain.
organisation
Vectra AI Launches Ascent
Related:
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
To stay safe Kaspersky recommends that users:
Be cautious with downloads.
organisation
Help Address New Era
Related:
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
To stay safe Kaspersky recommends that users:
Be cautious with downloads.
organisation
Kaspersky
Related:
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
To stay safe Kaspersky recommends that users:
Be cautious with downloads.
organisation
Kaspersky Next
Use all-encompassing solutions from the
Kaspersky Next
product line that provide real-time protection, threat visibility, and the investigation and response capabilities of EPP, EDR and XDR.
organisation
EPP
Use all-encompassing solutions from the
Kaspersky Next
product line that provide real-time protection, threat visibility, and the investigation and response capabilities of EPP, EDR and XDR.
organisation
EDR
Use all-encompassing solutions from the
Kaspersky Next
product line that provide real-time protection, threat visibility, and the investigation and response capabilities of EPP, EDR and XDR.
organisation
XDR
Use all-encompassing solutions from the
Kaspersky Next
product line that provide real-time protection, threat visibility, and the investigation and response capabilities of EPP, EDR and XDR.
organisation
InfoSec
Provide your InfoSec professionals with an in-depth visibility into cyberthreats targeting your organisation.
organisation
Cyber Immunity
Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.
organisation
Cybersecurity True to Business
Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime.
victims
200,000 organizations
Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients.
September 21, 2026
Kaspersky's Global Research and Analysis Team discovered a multi-stage campaign targeting individual users and organizations on September 21, 2026.
Click on any entity below to view its context and source!
source_region
Kenya
PRESS RELEASENAIROBI, Kenya , September 21, 2026 —
Kaspersky
's Global Research and Analysis Team (GReAT) has uncovered a sophisticated new multi-stage campaign targeting both individual users and organisations.
organisation
Global Research and Analysis Team
PRESS RELEASENAIROBI, Kenya , September 21, 2026 —
Kaspersky
's Global Research and Analysis Team (GReAT) has uncovered a sophisticated new multi-stage campaign targeting both individual users and organisations.
Tactical Metrics
Metrics
infrastructure
Ios
Affected Product
Click for context!
*Affected Devices: Smart TV by Phillips and an iOS device.
Metrics
infrastructure
Windows
Affected Product
These modules allow it to establish persistence, so it remains on the system after a reboot even after it has been terminated, bypass User Account Control (UAC) to gain administrator privileges in Windows without triggering the usual warning prompt and ultimately provide the attackers with remote access to the compromised machine.
Metrics
victims
200,000
Organizations
Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients.
Intelligence Sources
Dark Reading
2026-09-21
AlienVault OTX
2026-09-08
Aenjaris -> (Sa Attack Indicators)
AlienVault OTX
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:08
Comprehensive Tactical Telemetry
Highly Correlated Entities
16x
organisation
Identified Entity
Ransomware
entity
6x
source region
Origin Country
Kenya
country
5x
target region
Target Country
France
country
3x
industry
Targeted Sector
Government
sector
2x
infrastructure
Affected Product
Ios
software
2x
timeline
Temporal Reference
September 21, 2026
date
Contextual Telemetry
Context Block
4 METRICS
tactic
Cyber Operation Type
Ransomware
tactic
tactic
MITRE ATT&CK Technique
T1588.001 - Malware
technique
threat actor
APT Group
ShinyHunters
actor
victims
Organizations
200,000
organizations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.