# What happened Attackers poisoned movie torrent downloads to deliver a Windows malware framework called MovieReaper. Victims who clicked magnet links or downloaded modified torrent files got a malicious executable that was disguised as a movie release. Securelist shared findings with Cyber Security News (CSN), reporting several hundred victims across multiple countries and sectors.
# How the bait works The malicious file is presented as a familiar movie filename with a long title that hides the.exe extension, for example: "the odyssey (2026) [1080p] [webrip] [5.1].exe". The loader uses a common application icon and the same MD5 hash across downloads, relying on social engineering to persuade victims to run it.
# Execution and persistence
The final module is modular and gives operators broad file-control abilities: read, upload, download, rename, move, delete, and generate previews or thumbnails. Additional capabilities can be delivered later by operators as needed.
# Why Solana is used for C2 MovieReaper's shellcode queries a specific Solana account via the getAccountInfo endpoint and decodes an encrypted address stored in the account data. That decrypted address points to a later command-and-control destination. Using Solana in this way lets attackers update destination data without relying on a single conventional infrastructure, complicating takedown efforts. This approach does not make the malware invisible, but it raises resilience against simple domain or IP blocks.
Previous campaigns, such as a developer-targeting Glassworm campaign, have used Solana for similar purposes, showing a trend of using public blockchain services to provide flexible instructions to malware.
# Scope and victims Securelist and CSN identified infections spanning Europe, Asia, and Africa, including private users and organizations in government, IT, retail, transport, consulting, and agriculture. Countries mentioned include Russia, Türkiye, Japan, Kenya, Uganda, Colombia, Spain, the Netherlands, Belgium, and Germany.
# Indicators of compromise (IoCs)
- Domain: itorrents[.]org (public torrent repository reported as compromised)
- Filename example: the odyssey (2026) [1080p] [webrip] [5.1].exe
- MD5 hash: 4334BBAEA8DE3
Security teams should compare these IoCs with local telemetry and searches for unusually long filename executables that appear to be media content.
# Practical defensive steps
- Block the IoCs listed and search endpoint logs for the MD5 and suspicious movie-named executables.
- Investigate systems that recently downloaded or executed torrent files, especially if the execution involved in-memory stages or UAC bypass indicators.
- Educate users to avoid pirated downloads and unverified installers. Do not disable security protections to run suspect files.
- Treat any system with evidence of these behaviors as compromised and follow incident response procedures to contain and remediate.
# Bottom line