A newly discovered malware framework dubbed MovieReaper has infected several hundred victims across Europe, Asia, and Africa by exploiting a single point of failure in the torrent ecosystem: a shared file repository that multiple tracker sites depend on to serve content.
Kaspersky’s Global Research and Analysis Team (GReAT) disclosed the campaign on September 17, 2026, tracing infections disguised as popular movies, most notably Christopher Nolan’s The Odyssey, back to a compromise of itorrents[.]org rather than any individual tracker.
Once installed, the malware can compromise the victim’s device and potentially steal sensitive information.
The incident highlights the risks of downloading files from unofficial torrent websites and unknown sources.MovieReaper malware has been distributed to torrent users in 15+ countries through a compromised iTorrents website.
Attackers used the platform to trick users into downloading malicious files disguised as movies or related content.
MovieReaper Malware Hits Torrent Users
Kaspersky researchers first spotted the campaign in mid-August 2026 during routine threat-hunting work, noticing that every victim they examined shared one thing: torrent usage.
Rather than breaching trackers like 1337x one by one, the attackers compromised itorrents[.]org, a public repository trackers rely on to resolve magnet links.
When a user clicks a magnet link, the poisoned archive silently substitutes a malicious torrent file for the requested content. As of publication, the repository remained compromised, meaning the threat was still live.

The loader identical in hash (MD5: A0B13781EDD7CFDAB13D79AFFF3C83C1) across dozens of disguised filenames such as “the odyssey (2026) [1080p] [webrip] [5.1].exe” uses deliberately long filenames and familiar icons to bury the .exe extension.
Once launched, it avoids conventional API calls like LoadLibrary, instead manually walking the PEB’s loader data to resolve functions and evade sandbox detection. It then fetches shellcode over HTTP from deadhub[.]org, falling back to a hardcoded IP if that fails.
The second stage adds a resilience layer rarely seen in commodity crimeware: it queries the Solana blockchain’s public RPC endpoint to retrieve an encrypted address for its actual command-and-control server, making the C2 infrastructure far harder to take down through conventional domain or IP blocking.
Later stages perform a UAC bypass, masquerade as msedge.exe inside the Windows Telemetry folder for persistence, and ultimately deploy a “file manager” module with 21 commands enabling attackers to browse, read, copy, rename, delete, and exfiltrate previews of files on the infected host.
Victims span individuals and organizations in Russia, Türkiye, Japan, Kenya, Uganda, Colombia, Spain, the Netherlands, Belgium, and Germany, among others, hitting sectors including government, IT, consulting, retail, transportation, and agriculture.
Kaspersky links the actor’s activity back to October 2025, noting the malware has grown stealthier over time while retaining its core signature: encrypted strings, HTTP-delivered shellcode fragments, and layered anti-sandbox checks. Kaspersky products detect the threat as HEUR:Trojan.Win64.Agent.gen.
Kaspersky notes that the first-stage infrastructure a single domain and IP serving the initial shellcode represents the clearest disruption point, since killing it would sever the entire chain before the blockchain-resilient second stage activates.
Still, researchers warn the framework’s modularity and in-memory execution model make it readily reusable in future campaigns, and until itorrents[.]org is fully remediated, any torrent resolving through it should be treated as untrusted.
Site: Thecyberdef.com
Follow TheCyberDef on Google News, LinkedIn & X for the latest cybersecurity updates. Stay informed.