Post

MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide

MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide

MovieReaper Malware Campaign 🚨

In mid-August 2026, Kaspersky researchers discovered a large-scale malware campaign affecting computer systems across multiple countries. They identified a previously unknown modular framework named “MovieReaper,” which spreads through a compromised torrent file repository. Now, the company has identified several hundred victims, including individual users and organizations.

Kaspersky detects the malware as HEUR:Trojan.Win64.Agent.gen. The campaign affected users and organizations across Europe, Asia, and Africa, with infections identified in countries including Russia, Türkiye, Japan, Kenya, Spain, and Germany. Affected organizations represented several sectors, including government, enterprise, IT, consulting, retail, transportation, and agriculture.

How It Works 🔍

MovieReaper took advantage of the same habit, targeting a source used by multiple torrent trackers. They compromised itorrents.org, a public repository of torrent files, allowing malicious torrent files to be sent to users through trackers relying on the repository. When users attempted to download torrents through magnet links, the compromised repository could return a different, malicious torrent file that led to the MovieReaper loader.

One executable seen by Kaspersky was named the odyssey (2026) (1080p) (webrip) (5.1).exe. Running this file launches the first-stage loader, which checks for security tools and sandbox environments before continuing the infection.

Multi-Stage Attack 🚀

Inside MovieReaper’s multi-stage attack, the loader downloads shellcode from its first C2 server before the malware turns to the Solana blockchain to obtain the address of another C2 server. This gives the attackers a way to change the next server address without putting it directly into the malware, making the later infrastructure harder to disrupt through conventional blocking and takedowns.

A later stage bypasses User Account Control (UAC), establishes persistence, and loads additional modules. Its final file manager contains 21 commands that let attackers upload, download, read, create, copy, rename, move, and delete files, while also retrieving file and image previews.

Kaspersky also found related activity dating back to October 2025. The researchers noted that the campaign has evolved over time, including modifications to the loader that make it harder to detect. The framework’s modular design and in-memory execution could also make it easier to reuse in future campaigns.

Warning Signs ⚠️

The filename used in this campaign is a warning sign on its own. A movie download ending in .exe is an executable, not a video file, so avoid running it. A legitimate movie file would have a video format like .mp4 or .mkv, not .exe. Avoiding unofficial movie downloads in the first place removes the initial step attackers need to start an infection.

Read full article

This post is licensed under CC BY 4.0 by the author.