The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
A sophisticated, modular malware campaign dubbed MovieReaper has been targeting users globally, primarily through compromised torrent trackers. The campaign, originating in late 2025, leverages a previously unknown framework that disguises itself as popular movies downloaded via torrents. Attackers utilize a Solana blockchain to distribute C2 addresses, making takedown efforts more difficult. The malware employs various techniques to evade detection by antivirus software and sandboxes, including obfuscation, memory execution, and UAC bypass to maintain persistence. The campaign has affected individuals and organizations across multiple countries, including Russia, Spain, Germany, and others, spanning sectors like enterprise, government, and IT. The campaign’s modular design and use of blockchain make it a resilient threat, and blocking the initial C2 server is a key mitigation strategy.
A sophisticated, modular malware campaign dubbed MovieReaper has been targeting users globally, primarily through compromised torrent trackers. The campaign, originating in late 2025, leverages a previously unknown framework that disguises itself as popular movies downloaded via torrents. Attackers utilize the Solana blockchain to distribute C2 addresses, making takedown efforts more difficult. The malware employs various techniques to evade detection by antivirus software and sandboxes, including obfuscation, memory execution, and UAC bypass to maintain persistence. The campaign has affected individuals and organizations across multiple countries, including Russia, Spain, Germany, and others, spanning sectors like enterprise, government, and IT.
Researchers at Kaspersky discovered MovieReaper during threat hunting efforts, noting a large-scale infection campaign involving previously unknown malware disguised as popular movies. The campaign targeted both individuals and organizations across Europe, Asia, and Africa, with infection attempts identified in countries including Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana, and others. The targeted organizations span a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.
Compromised torrent trackers are the primary vector used to distribute the malware. Attackers did not compromise the torrent trackers themselves, but instead compromised a widely used public repository of torrent files – itorrents[.]org. As a result, torrent trackers relying on this repository inadvertently distributed malicious torrent files to their users. The initial infection chain consists of several steps, with the first stage dropped on disk before execution to avoid detection. The malware itself is not heavily obfuscated, apart from the use of a custom stream cipher to encrypt strings. The campaign has evolved over time, with the malware authors expanding their arsenal and making the loader harder to detect, while maintaining a consistent pattern of downloading shellcode via plain HTTP and utilizing blockchain for C2 distribution.
Indicators of compromise include specific file hashes, file paths (such as %ProgramData%\Microsoft\Windows\Telemetry\msedge.exe), and mutexes (Global\E4AyDKzvEhe2hgAr, Global\fnulSktzSqvVLXHU). The campaign utilizes a Solana blockchain via api.mainnet.solana.com for C2, making it more resilient to traditional takedown efforts. The final module (“file manager”) exposes 21 commands that allow remote operators to access the victim’s system, including file manipulation and execution capabilities.
Blocking the initial C2 server (deadhub[.]org and 193.23.118[.]155) and the second-stage C2 (208.64.33[.]90 and 208.94.246[.]53) are key mitigation strategies. The modular design and use of blockchain make it a resilient threat, and continued monitoring of the actor's activity is recommended.
