Hackers Poison Movie Torrents With MovieReaper Malware That Uses Solana for C2
Poisoned movie torrents deliver MovieReaper malware using Solana blockchain for resilient C2, infecting several hundred victims across multiple continents.
Securelist reports a new Windows malware framework dubbed MovieReaper distributed through poisoned torrent downloads of popular films, with several hundred victims identified across Europe, Asia, and Africa, including organizations in government, IT, retail, transport, consulting, and agriculture. A loader disguised as a movie release file runs staged payloads largely in memory, installs persistence masquerading as Windows telemetry (msedge.exe under ProgramData), bypasses UAC, and grants operators broad file access for data theft. Unusually, the shellcode queries a Solana account via getAccountInfo to decode later command-and-control addresses, complicating takedowns, and the second stage uses HTTPS with a pinned certificate. Actor activity dates back to October 2025 and involves a compromised public torrent-file repository.