New MovieReaper Malware Campaign Targets Users via Compromised Torrent Trackers

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

New MovieReaper Malware Campaign Exploits Torrent Trackers

The rise of torrent trackers as a means for distributing malicious software has been a persistent issue in the cybersecurity landscape. Cybercriminals have long exploited these platforms, disguising malware as popular films, games, and other content. Recent research from Kaspersky has unveiled a new modular malware framework, dubbed MovieReaper, which has been deployed through compromised torrent tracker file storage. This campaign has already affected several hundred victims across various countries, including Russia, Türkiye, Japan, and several European nations. The full details of this campaign can be found in Kaspersky’s report here.

Technical Overview of the MovieReaper Framework

In mid-August 2026, Kaspersky’s threat-hunting efforts uncovered a large-scale infection campaign utilizing previously unknown malware masquerading as popular movies. The common thread among the victims was their use of torrent trackers, prompting further investigation into the malware’s distribution mechanisms and overall scope.

The primary vector for this malware is compromised torrent trackers. Kaspersky’s analysis revealed that the attackers did not directly compromise the torrent trackers themselves but instead targeted a widely used public repository of torrent files, itorrents[.]org. This allowed them to distribute malicious torrent files to users across multiple trackers without needing to infiltrate each platform individually. As of the report’s publication, this repository remains compromised, leading users to download malware-laden files instead of the intended content.

Infection Chain and Malware Implants

The infection process initiated by MovieReaper consists of several stages, with only the first stage being dropped onto the disk to evade detection. The malware employs a custom stream cipher for string encryption, primarily focusing on avoiding detection by antivirus sandboxes.

  • Step 1: Loader – The initial executable is distributed under various names, with a consistent file hash across downloads. Upon execution, it establishes a global mutex to prevent multiple instances and performs operations to avoid detection.
  • Step 2: Shellcode – The loader makes an HTTPS request to the Solana blockchain to retrieve the address of a second command-and-control (C2) server, enhancing the malware’s resilience against takedown efforts.
  • Step 3: UAC Bypass and Persistence – The malware employs techniques to bypass User Account Control (UAC) and achieves persistence by masquerading as a legitimate Windows process.
  • Step 4: Final Implant – The final module grants the operator extensive filesystem access, allowing for file manipulation and exfiltration.

Victim Profile and Global Impact

The MovieReaper campaign has targeted a diverse range of victims, including individuals and organizations across Europe, Asia, and Africa. Infection attempts have been reported in countries such as Russia, Spain, Germany, and Kenya, affecting sectors like government, IT, retail, and agriculture. This widespread impact underscores the campaign’s potential to disrupt various industries and highlights the need for robust cybersecurity measures.

Conclusions and Future Monitoring

Kaspersky’s research indicates that the same threat actor has been active since at least October 2025, with the campaign evolving over time. The modular nature of the MovieReaper framework allows for easy adaptation in future attacks. The first stage of the infection chain presents a clear opportunity for disruption, as it relies on a specific domain and IP address. However, the use of the Solana blockchain for subsequent stages complicates conventional takedown efforts.

As the cybersecurity community continues to monitor this actor’s activities, the potential for new threats remains high. The findings from this campaign serve as a reminder of the persistent risks associated with torrent usage and the importance of maintaining vigilant cybersecurity practices.

Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

North Korean hackers steal over $10.5 million in cryptocurrency through ‘WaterPlum’ campaign targeting job seekers across 100 countries

North Korean hackers have reportedly stolen over $10.5 million in cryptocurrency through a campaign known as "WaterPlum," which targets job seekers across more than...

UAE Cyber Security Council and Fortinet Launch Internship Program for Emirati Students

The UAE Cyber Security Council (CSC) has partnered with Fortinet to launch a new cybersecurity internship programme aimed at equipping Emirati university students with...

AWS AgentCore Harness Vulnerability Allows Credential Exfiltration via Prompt Injection

Recent research from Unit 42 has uncovered a significant vulnerability in Amazon Web Services (AWS) AgentCore Harness, which could allow attackers to exfiltrate plaintext...

Germany’s F127 frigate program faces scrutiny over U.S. technology reliance

Germany's F127 frigate program faces scrutiny over U.S. technology reliance The German Navy's future F127 class air defense frigates are set to be equipped with...