Skip to content

MovieReaper

MovieReaper is a modular, multi-stage Windows crimeware framework distributed through malicious torrent files masquerading as popular films and other pirated content.

Profile source: Mallory opens in a new tab

MovieReaper

Family profile

MovieReaper is a modular, multi-stage Windows crimeware framework distributed through malicious torrent files masquerading as popular films and other pirated content. The campaign abuses a compromised public torrent-file repository, causing magnet-link requests to retrieve substituted torrents that download a malicious loader. The loader employs anti-analysis measures and memory-resident execution, retrieves shellcode, and uses the Solana blockchain as a decentralized mechanism for resolving later-stage command-and-control infrastructure. Subsequent components communicate over HTTPS with certificate pinning, load COFF modules directly into memory, bypass Windows User Account Control, and establish persistence while masquerading as a legitimate telemetry-related executable. A known final module provides remote filesystem management, including directory enumeration, file reading, transfer, creation, copying, renaming, moving, deletion, permission modification, symbolic-link creation, and file or image previews that facilitate data collection and exfiltration. Activity associated with an unidentified actor has been observed since at least October 2025 and has affected individual users and organizations across Europe, Asia, and Africa, including government, IT, consulting, retail, transportation, and agriculture sectors.

Capabilities

  • Defense Evasion
  • Exfiltration
  • Persistence
  • Post Exploitation
  • Privilege Escalation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 18, 2026
Last activity
Sep 18, 2026
Feed role
C2
Host form
0 IP / 1 hostnames

Leading locations

  • US1

Leading providers

  • Cloudflare, Inc.1

Infrastructure traits

  • Anycast 1
  • Hosting 1

MITRE ATT&CK

MovieReaper in ATT&CK

27 distinct techniques

Reporting

Research mentioning MovieReaper

Sep 17
Pcmag

iTorrents.org Compromised To Spread Windows Malware, Kaspersky Says | PCMag

A previously unknown modular crimeware framework, MovieReaper, was distributed through malicious torrent files masquerading as popular films—including The Odyssey—after attackers compromised the public torrent-file repository itorrents.org. Active since at least October 2025 and identified in mid-August 2026, the campaign has affected individual and organizational victims across Europe, Asia, Africa, and other regions without requiring the attackers to compromise each torrent tracker directly. The Trojan uses sandbox evasion and in-memory shellcode execution, initially retrieving payloads from deadhub.org or fallback address 193.23.118.155. It obtains an encrypted second-stage C2 address through the Solana blockchain, downloads COFF modules over HTTPS using certificate pinning, bypasses UAC, and persists as a fake msedge.exe telemetry process. Its final known modules enable broad filesystem operations and prepare data for exfiltration; blocking the identified first-stage infrastructure may interrupt infections before they transition to the more resilient blockchain-mediated C2 chain.

Sep 17
Malware News

The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents - Malware News - Malware Analysis, News and Indicators

Sep 17
Securelist

MovieReaper: Trojan attack via movie torrents, including “The Odyssey | Securelist

Sep 17
Securelist Ru

MovieReaper: троянская атака через торренты с фильмами, включая "Одиссею" | Securelist

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.