Last seven days
- First activity
- Sep 18, 2026
- Last activity
- Sep 18, 2026
- Feed role
- C2
- Host form
- 0 IP / 1 hostnames
MovieReaper is a modular, multi-stage Windows crimeware framework distributed through malicious torrent files masquerading as popular films and other pirated content.
Profile source: Mallory opens in a new tabMovieReaper
MovieReaper is a modular, multi-stage Windows crimeware framework distributed through malicious torrent files masquerading as popular films and other pirated content. The campaign abuses a compromised public torrent-file repository, causing magnet-link requests to retrieve substituted torrents that download a malicious loader. The loader employs anti-analysis measures and memory-resident execution, retrieves shellcode, and uses the Solana blockchain as a decentralized mechanism for resolving later-stage command-and-control infrastructure. Subsequent components communicate over HTTPS with certificate pinning, load COFF modules directly into memory, bypass Windows User Account Control, and establish persistence while masquerading as a legitimate telemetry-related executable. A known final module provides remote filesystem management, including directory enumeration, file reading, transfer, creation, copying, renaming, moving, deletion, permission modification, symbolic-link creation, and file or image previews that facilitate data collection and exfiltration. Activity associated with an unidentified actor has been observed since at least October 2025 and has affected individual users and organizations across Europe, Asia, and Africa, including government, IT, consulting, retail, transportation, and agriculture sectors.
C2 tracking
Derp observations, rolling seven-day window
MITRE ATT&CK
Reporting
A previously unknown modular crimeware framework, MovieReaper, was distributed through malicious torrent files masquerading as popular films—including The Odyssey—after attackers compromised the public torrent-file repository itorrents.org. Active since at least October 2025 and identified in mid-August 2026, the campaign has affected individual and organizational victims across Europe, Asia, Africa, and other regions without requiring the attackers to compromise each torrent tracker directly. The Trojan uses sandbox evasion and in-memory shellcode execution, initially retrieving payloads from deadhub.org or fallback address 193.23.118.155. It obtains an encrypted second-stage C2 address through the Solana blockchain, downloads COFF modules over HTTPS using certificate pinning, bypasses UAC, and persists as a fake msedge.exe telemetry process. Its final known modules enable broad filesystem operations and prepare data for exfiltration; blocking the identified first-stage infrastructure may interrupt infections before they transition to the more resilient blockchain-mediated C2 chain.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.