MovieReaper malware delivered via compromised itorrents.org torrent repository uses Solana blockchain for resilient C2
Kaspersky uncovered MovieReaper (HEUR:Trojan.Win64.Agent.gen), a multi-stage Windows malware spread through pirated-movie torrents after attackers compromised the shared itorrents[.]org repository, infecting several hundred victims across multiple continents…
In mid-August 2026, Kaspersky identified a campaign distributing an unknown loader disguised as movie releases such as 'the odyssey (2026) [1080p] [webrip] [5.1].exe' (MD5 A0B13781EDD7CFDAB13D79AFFF3C83C1) with the .exe extension hidden, detected as HEUR:Trojan.Win64.Agent.gen. Rather than compromising the trackers themselves, the attackers compromised the shared itorrents[.]org torrent-file repository, poisoning magnet-link downloads across multiple dependent tracker sites at once; the repository remained compromised at publication (2026-09-17). Several hundred victims — individuals and organizations in Russia, Türkiye, Japan, Kenya, Uganda, Colombia and several European countries — were infected, spanning enterprise, government, IT, retail, transportation, consulting and agriculture sectors across Europe, Asia, Africa and Latin America. Sources disagree on the victim-country count: Kaspersky cites victims in at least ten countries, while GBHackers reports 11+ countries, and Cyber Security News lists continents as Europe, Asia and Africa only. The loader fetches shellcode from deadhub[.]org (with HTTP fallback to IP 193.23.118[.]155) via fake .png/.jpg paths, maps it into RWX memory, and evades sandboxes via PEB traversal, direct syscalls and custom stream-cipher string encryption. A second-stage implant resolves XOR-encrypted C2 addresses through Solana getAccountInfo queries to a hardcoded on-chain account — letting operators reroute infrastructure on-chain and complicating takedowns — and communicates over HTTPS with a pinned certificate. A later module bypasses UAC, masquerades as msedge.exe in the Windows Telemetry path under ProgramData for persistence, and deploys a 21-command remote file manager granting operators broad file access for data theft. Per Cyber Security News, actor activity dates back to October 2025.
- Attackers compromised the itorrents[.]org torrent-file repository (not the trackers), poisoning magnet-link downloads across multiple dependent tracker sites; the repository remained compromised at publication (2026-09-17)
- Loader disguised as movie releases such as 'the odyssey (2026) [1080p] [webrip] [5.1].exe' with hidden .exe extension; identical MD5 A0B13781EDD7CFDAB13D79AFFF3C83C1 across samples; detected as HEUR:Trojan.Win64.Agent.gen
- Several hundred victims, individuals and organizations, in Russia, Türkiye, Japan, Kenya, Uganda, Colombia and several European countries; sectors include enterprise, government, IT, retail, transportation, consulting and agriculture…
- Country-count discrepancy: Kaspersky cites at least ten countries; GBHackers reports 11+; Cyber Security News lists Europe, Asia and Africa only
- Loader fetches shellcode from deadhub[.]org with HTTP fallback to IP 193.23.118[.]155, using fake .png/.jpg paths, mapping it into RWX memory
- Sandbox evasion via PEB traversal, direct syscalls, and custom stream-cipher string encryption
- Second-stage implant resolves XOR-encrypted C2 addresses via Solana getAccountInfo queries to a hardcoded on-chain account, enabling on-chain infrastructure rerouting and complicating takedowns; uses HTTPS with a pinned certificate
- Later module bypasses UAC, masquerades as msedge.exe in the Windows Telemetry path under ProgramData for persistence, and deploys a 21-command remote file manager for data theft
Coverage timelineoldest first · each row is one article
- · 1d agoThe Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
Kaspersky Securelist· 64
Kaspersky uncovers MovieReaper, a multi-stage malware framework spread via compromised itorrents.org torrent files, hitting hundreds of users.
- · 10h agoMovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2
GBHackers· 68
Kaspersky reports MovieReaper malware distributed via compromised torrent repository itorrents.org, using Solana blockchain for resilient C2 across four continents.
- · 7h agoHackers Poison Movie Torrents With MovieReaper Malware That Uses Solana for C2
Cyber Security News· 55
Poisoned movie torrents deliver MovieReaper malware using Solana blockchain for resilient C2, infecting several hundred victims across multiple continents.