ZeroHour
Story · 3 sources · 3 articlesfirst updated ()1

MovieReaper malware delivered via compromised itorrents.org torrent repository uses Solana blockchain for resilient C2

highMalwareexploited in the wildimportance 68
What's new: Compared with the previous summary (2026-09-18T05:09:51Z), the merged story adds Cyber Security News details: actor activity dating back to October 2025, the second stage's use of HTTPS with a pinned certificate, persistence as msedge.exe specifically under ProgramData, the hidden .exe extension on the loader filename, and the addition of the consulting sector to the victim list. The previously…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Kaspersky uncovered MovieReaper (HEUR:Trojan.Win64.Agent.gen), a multi-stage Windows malware spread through pirated-movie torrents after attackers compromised the shared itorrents[.]org repository, infecting several hundred victims across multiple continents…

In mid-August 2026, Kaspersky identified a campaign distributing an unknown loader disguised as movie releases such as 'the odyssey (2026) [1080p] [webrip] [5.1].exe' (MD5 A0B13781EDD7CFDAB13D79AFFF3C83C1) with the .exe extension hidden, detected as HEUR:Trojan.Win64.Agent.gen. Rather than compromising the trackers themselves, the attackers compromised the shared itorrents[.]org torrent-file repository, poisoning magnet-link downloads across multiple dependent tracker sites at once; the repository remained compromised at publication (2026-09-17). Several hundred victims — individuals and organizations in Russia, Türkiye, Japan, Kenya, Uganda, Colombia and several European countries — were infected, spanning enterprise, government, IT, retail, transportation, consulting and agriculture sectors across Europe, Asia, Africa and Latin America. Sources disagree on the victim-country count: Kaspersky cites victims in at least ten countries, while GBHackers reports 11+ countries, and Cyber Security News lists continents as Europe, Asia and Africa only. The loader fetches shellcode from deadhub[.]org (with HTTP fallback to IP 193.23.118[.]155) via fake .png/.jpg paths, maps it into RWX memory, and evades sandboxes via PEB traversal, direct syscalls and custom stream-cipher string encryption. A second-stage implant resolves XOR-encrypted C2 addresses through Solana getAccountInfo queries to a hardcoded on-chain account — letting operators reroute infrastructure on-chain and complicating takedowns — and communicates over HTTPS with a pinned certificate. A later module bypasses UAC, masquerades as msedge.exe in the Windows Telemetry path under ProgramData for persistence, and deploys a 21-command remote file manager granting operators broad file access for data theft. Per Cyber Security News, actor activity dates back to October 2025.

  • Attackers compromised the itorrents[.]org torrent-file repository (not the trackers), poisoning magnet-link downloads across multiple dependent tracker sites; the repository remained compromised at publication (2026-09-17)
  • Loader disguised as movie releases such as 'the odyssey (2026) [1080p] [webrip] [5.1].exe' with hidden .exe extension; identical MD5 A0B13781EDD7CFDAB13D79AFFF3C83C1 across samples; detected as HEUR:Trojan.Win64.Agent.gen
  • Several hundred victims, individuals and organizations, in Russia, Türkiye, Japan, Kenya, Uganda, Colombia and several European countries; sectors include enterprise, government, IT, retail, transportation, consulting and agriculture…
  • Country-count discrepancy: Kaspersky cites at least ten countries; GBHackers reports 11+; Cyber Security News lists Europe, Asia and Africa only
  • Loader fetches shellcode from deadhub[.]org with HTTP fallback to IP 193.23.118[.]155, using fake .png/.jpg paths, mapping it into RWX memory
  • Sandbox evasion via PEB traversal, direct syscalls, and custom stream-cipher string encryption
  • Second-stage implant resolves XOR-encrypted C2 addresses via Solana getAccountInfo queries to a hardcoded on-chain account, enabling on-chain infrastructure rerouting and complicating takedowns; uses HTTPS with a pinned certificate
  • Later module bypasses UAC, masquerades as msedge.exe in the Windows Telemetry path under ProgramData for persistence, and deploys a 21-command remote file manager for data theft

Coverage timeline

  1. · 1d ago
    Kaspersky Securelist· 64
    The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

    Kaspersky uncovers MovieReaper, a multi-stage malware framework spread via compromised itorrents.org torrent files, hitting hundreds of users.

  2. · 10h ago
    GBHackers· 68
    MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2

    Kaspersky reports MovieReaper malware distributed via compromised torrent repository itorrents.org, using Solana blockchain for resilient C2 across four continents.

  3. · 7h ago
    Cyber Security News· 55
    Hackers Poison Movie Torrents With MovieReaper Malware That Uses Solana for C2

    Poisoned movie torrents deliver MovieReaper malware using Solana blockchain for resilient C2, infecting several hundred victims across multiple continents.