New MovieReaper Malware Campaign Targets Users via Compromised Torrent Trackers

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

New MovieReaper Malware Campaign Exploits Torrent Trackers

The rise of torrent trackers as a means for distributing malicious software has been a persistent issue in the cybersecurity landscape. Cybercriminals have long exploited these platforms, disguising malware as popular films, games, and other content. Recent research from Kaspersky has unveiled a new modular malware framework, dubbed MovieReaper, which has been deployed through compromised torrent tracker file storage. This campaign has already affected several hundred victims across various countries, including Russia, Türkiye, Japan, and several European nations. The full details of this campaign can be found in Kaspersky’s report here.

Technical Overview of the MovieReaper Framework

In mid-August 2026, Kaspersky’s threat-hunting efforts uncovered a large-scale infection campaign utilizing previously unknown malware masquerading as popular movies. The common thread among the victims was their use of torrent trackers, prompting further investigation into the malware’s distribution mechanisms and overall scope.

The primary vector for this malware is compromised torrent trackers. Kaspersky’s analysis revealed that the attackers did not directly compromise the torrent trackers themselves but instead targeted a widely used public repository of torrent files, itorrents[.]org. This allowed them to distribute malicious torrent files to users across multiple trackers without needing to infiltrate each platform individually. As of the report’s publication, this repository remains compromised, leading users to download malware-laden files instead of the intended content.

Infection Chain and Malware Implants

The infection process initiated by MovieReaper consists of several stages, with only the first stage being dropped onto the disk to evade detection. The malware employs a custom stream cipher for string encryption, primarily focusing on avoiding detection by antivirus sandboxes.

  • Step 1: Loader – The initial executable is distributed under various names, with a consistent file hash across downloads. Upon execution, it establishes a global mutex to prevent multiple instances and performs operations to avoid detection.
  • Step 2: Shellcode – The loader makes an HTTPS request to the Solana blockchain to retrieve the address of a second command-and-control (C2) server, enhancing the malware’s resilience against takedown efforts.
  • Step 3: UAC Bypass and Persistence – The malware employs techniques to bypass User Account Control (UAC) and achieves persistence by masquerading as a legitimate Windows process.
  • Step 4: Final Implant – The final module grants the operator extensive filesystem access, allowing for file manipulation and exfiltration.

Victim Profile and Global Impact

The MovieReaper campaign has targeted a diverse range of victims, including individuals and organizations across Europe, Asia, and Africa. Infection attempts have been reported in countries such as Russia, Spain, Germany, and Kenya, affecting sectors like government, IT, retail, and agriculture. This widespread impact underscores the campaign’s potential to disrupt various industries and highlights the need for robust cybersecurity measures.

Conclusions and Future Monitoring

Kaspersky’s research indicates that the same threat actor has been active since at least October 2025, with the campaign evolving over time. The modular nature of the MovieReaper framework allows for easy adaptation in future attacks. The first stage of the infection chain presents a clear opportunity for disruption, as it relies on a specific domain and IP address. However, the use of the Solana blockchain for subsequent stages complicates conventional takedown efforts.

As the cybersecurity community continues to monitor this actor’s activities, the potential for new threats remains high. The findings from this campaign serve as a reminder of the persistent risks associated with torrent usage and the importance of maintaining vigilant cybersecurity practices.

Follow Cyber Warriors Middle East for further cybersecurity features, analysis and insights.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Radaris.com and 14 Other Domains Transferred to Plaintiffs in New Jersey Privacy Lawsuit

The consumer data broker Radaris.com has recently faced legal repercussions for allegedly violating New Jersey's privacy law, known as Daniel’s Law. This law mandates...

Ransomware Activity in the Middle East Surges Over 20-Fold Amid Evolving Cyber Threats

Ransomware activity targeting the Middle East has surged dramatically, increasing from 17 threat intelligence feeds in April 2025 to 357 in June 2026—a staggering...

Cisco Warns of Active Exploitation of CVE-2026-76461 SQL Injection Vulnerability in Secure Email Gateway

Critical SQL Injection Vulnerability in Cisco Secure Email GatewayOn September 14, 2026, Cisco issued a security advisory regarding CVE-2026-76461, a critical SQL injection vulnerability...

BAM-IS submarine rescue vessel A-21 Poseidón named by Navantia

On September 18, 2026, Navantia celebrated the naming ceremony of the Spanish Navy’s new Underwater Intervention Maritime Action Vessel (BAM-IS), A-21 Poseidón. The ceremony follows...