Cybersecuritynews iconCybersecuritynewsSep 18, 2026 ~6 min source read

MovieReaper: Movie Torrents Are Delivering a New Windows Malware That Uses Solana for Command-and-Control

Attackers have poisoned popular movie torrent files to deliver a staged Windows malware framework called MovieReaper. The campaign uses social engineering, memory-only execution, and the Solana blockchain to make take-downs harder.

Hackers Poison Movie Torrents With MovieReaper Malware That Uses Solana for C2

Share this story

Send the public story page.

Useful takeaways from this story.

MovieReaper executes in memory, avoids common API calls, bypasses UAC, and installs a modular agent that can read, upload, and exfiltrate files.

The malware uses a Solana account to retrieve an encrypted C2 address, increasing resilience because attackers can change destination data without hosting a conventional server.

Block and investigate unusual torrent downloads, watch for the listed IoCs, and avoid running pirated or unverified installers on personal and work devices.

# What happened Attackers poisoned movie torrent downloads to deliver a Windows malware framework called MovieReaper. Victims who clicked magnet links or downloaded modified torrent files got a malicious executable that was disguised as a movie release. Securelist shared findings with Cyber Security News (CSN), reporting several hundred victims across multiple countries and sectors.

# How the bait works The malicious file is presented as a familiar movie filename with a long title that hides the.exe extension, for example: "the odyssey (2026) [1080p] [webrip] [5.1].exe". The loader uses a common application icon and the same MD5 hash across downloads, relying on social engineering to persuade victims to run it.

# Execution and persistence

The final module is modular and gives operators broad file-control abilities: read, upload, download, rename, move, delete, and generate previews or thumbnails. Additional capabilities can be delivered later by operators as needed.

# Why Solana is used for C2 MovieReaper's shellcode queries a specific Solana account via the getAccountInfo endpoint and decodes an encrypted address stored in the account data. That decrypted address points to a later command-and-control destination. Using Solana in this way lets attackers update destination data without relying on a single conventional infrastructure, complicating takedown efforts. This approach does not make the malware invisible, but it raises resilience against simple domain or IP blocks.

Previous campaigns, such as a developer-targeting Glassworm campaign, have used Solana for similar purposes, showing a trend of using public blockchain services to provide flexible instructions to malware.

# Scope and victims Securelist and CSN identified infections spanning Europe, Asia, and Africa, including private users and organizations in government, IT, retail, transport, consulting, and agriculture. Countries mentioned include Russia, Türkiye, Japan, Kenya, Uganda, Colombia, Spain, the Netherlands, Belgium, and Germany.

# Indicators of compromise (IoCs)

  • Domain: itorrents[.]org (public torrent repository reported as compromised)
  • Filename example: the odyssey (2026) [1080p] [webrip] [5.1].exe
  • MD5 hash: 4334BBAEA8DE3

Security teams should compare these IoCs with local telemetry and searches for unusually long filename executables that appear to be media content.

# Practical defensive steps

  • Block the IoCs listed and search endpoint logs for the MD5 and suspicious movie-named executables.
  • Investigate systems that recently downloaded or executed torrent files, especially if the execution involved in-memory stages or UAC bypass indicators.
  • Educate users to avoid pirated downloads and unverified installers. Do not disable security protections to run suspect files.
  • Treat any system with evidence of these behaviors as compromised and follow incident response procedures to contain and remediate.

# Bottom line

More context around this story.

Эксперт рассказал, как злоумышленники маскируют вредоносное ПО под торренты
Ria iconRiaSep 17, 2026

Эксперт рассказал, как злоумышленники маскируют вредоносное ПО под торренты

Злоумышленники маскируют вредоносное ПО под торренты с популярными фильмами, а после запуска оно получает удаленный доступ к устройству, рассказал эксперт по кибербезопасности Павел Черемушкин.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app