MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2
Kaspersky reports MovieReaper malware distributed via compromised torrent repository itorrents.org, using Solana blockchain for resilient C2 across four continents.
Kaspersky identified a multi-stage Windows malware framework, detected as HEUR:Trojan.Win64.Agent.gen, delivered through pirated movie torrents after operators compromised the shared repository itorrents[.]org, poisoning magnet-link downloads across multiple dependent tracker sites. The loader evades analysis via PEB walking, custom stream-cipher string encryption, and shellcode from deadhub[.]org, while a second-stage implant resolves C2 addresses through Solana getAccountInfo queries to a hardcoded on-chain account. A later module bypasses UAC and masquerades as msedge.exe in the Windows Telemetry path, ultimately deploying a 21-command remote file manager. Victims were detected in enterprise, government, IT, retail, transportation, and agriculture sectors across Europe, Asia, Africa, and Latin America.