
Findings and evidence
Kaspersky reconstructs a multistage malware campaign discovered during August research into blockchain-related command infrastructure. Its investigation links affected users of different torrent trackers to a shared torrent-file repository and documents several hundred observed victims.
Why it matters
A common upstream dependency can explain incidents that initially appear unrelated. Record the download origin and intermediate redirects alongside file hashes and endpoint events; this supports a defensible account of how an artifact arrived.
Scope and limits
The observed victim set reflects the publisher’s visibility. It is not a census of all affected users, and use of a torrent service alone is not evidence of infection.
Primary source
Kaspersky / Securelist: original publication. Source published 2026-09-17. Brief prepared by websec.gr on 26 September 2026. This is an editorial research summary, not a claim of independent replication.