The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrentsnew
Kaspersky uncovers MovieReaper, a multi-stage malware framework spread via compromised itorrents.org torrent files, hitting hundreds of users.
In mid-August 2026 Kaspersky identified a campaign distributing an unknown loader disguised as movies such as 'the odyssey (2026) [1080p] [webrip] [5.1].exe' (MD5 A0B13781EDD7CFDAB13D79AFFF3C83C1) through torrent trackers. The attackers compromised the itorrents[.]org torrent-file repository rather than the trackers themselves, so multiple platforms delivered malicious torrents; the repository remained compromised at publication. Several hundred victims, including individuals and organizations in Russia, Türkiye, Japan, Kenya, Uganda, Colombia and several European countries, were infected with the modular MovieReaper framework, detected as HEUR:Trojan.Win64.Agent.gen. The loader fetches shellcode from deadhub[.]org (fallback IP 193.23.118[.]155), maps it into RWX memory, and uses PEB traversal, encrypted strings and direct syscalls to evade sandboxes.