The infection chain | Image: Kaspersky
At a Glance
| Attribute | Details |
|---|---|
| Malware Family | MovieReaper |
| Threat Actor | Unknown cybercriminals |
| Target Victims | Hundreds of organizations and individuals globally |
| Delivery Vector | Compromised itorrents.org repository serving fake movie files |
| Key Capabilities | Solana blockchain C2, UAC bypass, remote file management |
| Source | Kaspersky Labs (Securelist) |
Executive Summary
The newly discovered MovieReaper malware infects victims downloading pirated films via compromised torrent files. After execution, this modular framework gives attackers complete remote file-management capabilities over infected systems. Furthermore, security experts warn that the campaign uses the Solana blockchain to resolve its command-and-control networks dynamically.
Malicious Torrent Delivery
Users attempting to pirate films often encounter malicious torrents instead of legitimate media files. Specifically, threat actors compromised the widely used itorrents.org public repository. Consequently, many different tracker websites inadvertently distribute booby-trapped downloads to their visitors. Kaspersky noted, “This approach is particularly powerful because the threat actors can reach users of multiple trackers without compromising each platform individually.”
The downloaded payload typically disguises itself as an executable file with a deceptively long name. For example, attackers used filenames like “the odyssey (2026) [1080p] [webrip] [5.1].exe” to trick users. Long filenames often push the executable extension out of view. Therefore, victims manually launch the file believing it is a video. In addition, community reports on Reddit confirm that many users recently noticed movie torrents arriving as executable files.
Evasive Infection Chain
When launched, the loader creates a global mutex to prevent multiple instances from running simultaneously. Next, the MovieReaper malware executes several checks to evade antivirus sandboxes and virtual machines. Rather than using standard Windows functions, it manually parses loaded libraries to locate required system addresses. Strings within the malware remain encrypted using a custom stream cipher.
After verifying the environment, the loader contacts a primary server over plain HTTP. It downloads shellcode disguised as innocuous image files. Subsequently, the malware maps this shellcode into read-write-execute memory. The executable hijacks a vectored exception handler to initiate the shellcode silently. Specifically, it relies on undocumented system calls instead of conventional thread creation mechanisms.
Decentralized Command and Control
The second-stage shellcode introduces a highly unusual command-and-control mechanism. It queries the Solana blockchain to retrieve an encrypted secondary server address. Attackers store this address within a specific Solana account data field. Consequently, they achieve decentralized infrastructure discovery that strongly resists conventional takedown efforts.
The implant communicates with its new server strictly over HTTPS using pinned certificates. Next, a loaded module bypasses Windows User Account Control to elevate its privileges. The malware establishes persistence by masquerading as a Microsoft Edge telemetry process. Finally, the respawned process bypasses initial checks and connects to receive the ultimate payload.
Data Exfiltration and File Management
The final stage delivers a capable file manager module directly into memory. This powerful tool exposes 21 distinct commands to remote operators. Attackers can read, upload, download, copy, move, rename, and delete files at will. Additionally, the MovieReaper malware torrent attacks can generate file thumbnails and image previews. This feature allows operators to inspect potentially valuable content before initiating full-scale data exfiltration. They avoid transferring massive junk files by previewing them first.
Kaspersky researchers suspect the threat actors can load additional specialized modules on demand. The campaign has already claimed several hundred victims since August 2026. Affected targets include government agencies, agricultural firms, and IT consultancies across Europe, Asia, Africa, and Latin America. Employees attempting to pirate media on corporate devices present a severe risk to organizational networks.
Defense and Detection Guidance
Organizations must block unauthorized torrent activity and enforce strict application-control policies. Administrators should investigate any endpoints attempting to execute movie-themed executable files. Furthermore, security teams must monitor for unusual binaries operating within the Windows Telemetry folder. Specifically, defenders should look for suspicious processes masquerading as the Microsoft Edge browser.
Defenders should also hunt for unexpected Solana RPC queries originating from corporate workstations. Endpoints generally have no legitimate business reason to query blockchain networks. Since the initial loader relies on a hardcoded primary domain, blocking this initial connection can successfully halt the infection chain. Continuous network monitoring remains critical to stop these decentralized crimeware campaigns.
Support Our Threat Intelligence
Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!