MovieReaper Malware Spreads Through Movie Torrents
An attempt to download a film through a familiar torrent tracker could infect a computer even without the tracker itself being hacked. Attackers compromised iTorrents.org, a popular repository of torrent files, and made the platforms that depend on the service unwittingly distribute malicious releases. The campaign has already affected several hundred private users and organizations across various countries. Kaspersky detailed the operation in its Securelist analysis of MovieReaper.
An Upstream Compromise, Not a Tracker Hack
Kaspersky specialists discovered the campaign in mid-August 2026, when they began dissecting previously unknown malware disguised as popular movies. The common trait of infected computers proved to be the use of torrent trackers, yet further investigation showed that the criminals had not hacked each platform separately. The point of distribution became iTorrents.org, a public cache from which various services obtain torrent files.
After the compromise, the repository could return to the user not the expected torrent but a substituted file leading to the download of a malicious program. At the time the research was published on September 17, iTorrents.org remained compromised. The substitution allowed the attackers to reach several torrent trackers using the shared service at once, instead of breaching each platform in turn.
Disguised as “The Odyssey”
The new malicious platform was named MovieReaper. One of the most widespread loaders posed as a copy of the 2026 film “The Odyssey” and was named the odyssey (2026) [1080p] [webrip] [5.1].exe. MovieReaper’s creators used long filenames and familiar application icons to make the .exe extension harder to notice. Infection began only after the user manually launched the program.
A Multi-Stage Infection
MovieReaper operates in several stages. The first loader inspects the environment and tries to determine whether the file is running inside a protective sandbox or a virtual machine. After passing the checks, the program contacts its command infrastructure, loads the next fragment of code directly into memory, and continues the infection without saving most components to disk.
At the next stage, the malware uses the Solana blockchain in an unusual way. MovieReaper addresses a particular account on the network and extracts from the data recorded there the address of a second C2 server. The blockchain in this case serves not for money transfers but becomes a resilient channel for delivering the address of the command infrastructure. Blocking a single IP address does not deprive the operators of the ability to change the value in the blockchain and redirect infected computers to another server.
Persistence and Remote File Access
The third stage bypasses Windows User Account Control, entrenches the malware in the system, and disguises the executable as C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. After a restart, MovieReaper skips part of the initial checks and more quickly loads the necessary modules from the command server.
The final discovered module effectively turns the infected computer into a remote file store under the attacker’s control. The operator receives 21 commands for browsing directories, and for reading, downloading, copying, renaming, moving, and deleting files. MovieReaper is also able to preview thumbnail images and file contents before a full data exfiltration. Researchers allow for the existence of additional modules that the server can load on request.
Hundreds of Victims Across Three Continents
Specialists identified several hundred victims among private users and organizations. Infection attempts were recorded in Russia, Spain, Germany, Finland, Turkey, Japan, Nepal, Kenya, Tanzania, Ghana, and other countries. Among the affected organizations were government structures, IT companies, consultancies, and enterprises in retail, transportation, and agriculture.
Traces of the same group’s activity could be followed back to at least October 2025. Over the intervening time, the developers complicated the loader and added further methods of evading automatic analysis. Researchers consider the first stage of infection the campaign’s most vulnerable point, since the initial code download depends on a single domain and a backup IP address. After the transition to the second stage, the infrastructure becomes more resilient thanks to the use of Solana and MovieReaper’s modular architecture.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.