ZeroHour
Country

Uganda

3 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

Hackers Poison Movie Torrents With MovieReaper Malware That Uses Solana for C2

Poisoned movie torrents deliver MovieReaper malware using Solana blockchain for resilient C2, infecting several hundred victims across multiple continents.

Securelist reports a new Windows malware framework dubbed MovieReaper distributed through poisoned torrent downloads of popular films, with several hundred victims identified across Europe, Asia, and Africa, including organizations in government, IT, retail, transport, consulting, and agriculture. A loader disguised as a movie release file runs staged payloads largely in memory, installs persistence masquerading as Windows telemetry (msedge.exe under ProgramData), bypasses UAC, and grants operators broad file access for data theft. Unusually, the shellcode queries a Solana account via getAccountInfo to decode later command-and-control addresses, complicating takedowns, and the second stage uses HTTPS with a pinned certificate. Actor activity dates back to October 2025 and involves a compromised public torrent-file repository.

Cyber Security News · 8h agoMalware in the wild 3 sources

MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2

Kaspersky reports MovieReaper malware distributed via compromised torrent repository itorrents.org, using Solana blockchain for resilient C2 across four continents.

Kaspersky identified a multi-stage Windows malware framework, detected as HEUR:Trojan.Win64.Agent.gen, delivered through pirated movie torrents after operators compromised the shared repository itorrents[.]org, poisoning magnet-link downloads across multiple dependent tracker sites. The loader evades analysis via PEB walking, custom stream-cipher string encryption, and shellcode from deadhub[.]org, while a second-stage implant resolves C2 addresses through Solana getAccountInfo queries to a hardcoded on-chain account. A later module bypasses UAC and masquerades as msedge.exe in the Windows Telemetry path, ultimately deploying a 21-command remote file manager. Victims were detected in enterprise, government, IT, retail, transportation, and agriculture sectors across Europe, Asia, Africa, and Latin America.

GBHackersupdated · 8h agofirst · 11h agoMalware in the wild 3 sources

The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

Kaspersky uncovers MovieReaper, a multi-stage malware framework spread via compromised itorrents.org torrent files, hitting hundreds of users.

In mid-August 2026 Kaspersky identified a campaign distributing an unknown loader disguised as movies such as 'the odyssey (2026) [1080p] [webrip] [5.1].exe' (MD5 A0B13781EDD7CFDAB13D79AFFF3C83C1) through torrent trackers. The attackers compromised the itorrents[.]org torrent-file repository rather than the trackers themselves, so multiple platforms delivered malicious torrents; the repository remained compromised at publication. Several hundred victims, including individuals and organizations in Russia, Türkiye, Japan, Kenya, Uganda, Colombia and several European countries, were infected with the modular MovieReaper framework, detected as HEUR:Trojan.Win64.Agent.gen. The loader fetches shellcode from deadhub[.]org (fallback IP 193.23.118[.]155), maps it into RWX memory, and uses PEB traversal, encrypted strings and direct syscalls to evade sandboxes.

Kaspersky Securelistupdated · 8h agofirst · 1d agoMalware in the wild 3 sources

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.