Decoding the world of cybersecurity

MovieReaper spreads through compromised torrent archive

Kaspersky says attackers compromised a shared torrent-file repository, causing multiple trackers to distribute a new multi-stage malware framework to users and organisations across several European countries.

MovieReaper spreads through compromised torrent archive
Summary
  • Kaspersky says MovieReaper has reached several hundred users and organisations across multiple countries, including several European markets.
  • Attackers compromised a shared torrent-file repository rather than the individual trackers that subsequently distributed the files.
  • The malware uses sandbox evasion, persistence, privilege elevation, remote-access modules, and Solana-based command infrastructure.

Attackers compromised a widely used repository of torrent files and turned it into a distribution point for a previously undocumented malware framework that has reached users and organisations across several European countries, according to research from Kaspersky.

The company’s Global Research and Analysis Team has named the malware MovieReaper and says several hundred victims have been identified across countries including Spain, the Netherlands, Belgium, and Germany, as well as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia.

Kaspersky says organisations affected by the campaign operate in sectors including government, IT, consulting, retail, transport, agriculture, and other enterprise environments. Those victim numbers and sector classifications derive from Kaspersky telemetry and have not been independently confirmed through disclosures by the affected organisations.

The campaign has been active since at least mid-August. Initial investigation pointed towards users of torrent trackers, but Kaspersky subsequently found that the trackers themselves had not been compromised.

Instead, attackers had compromised itorrents.org, a public repository used by multiple torrent services to retrieve torrent files. Trackers relying on that repository then distributed malicious torrent files to their users without needing to be compromised individually.

The technique gave the attackers a larger distribution surface from a single infrastructure breach. Users following magnet links could receive a different torrent file from the one expected, leading them towards a Windows executable disguised as popular film content.

Once the executable is launched manually, MovieReaper begins a multi-stage infection process. Kaspersky says the loader performs checks intended to detect antivirus sandboxes and analysis environments before contacting command infrastructure and loading later-stage components.

Subsequent stages provide persistence, bypass Windows User Account Control to gain elevated privileges, and support remote access to the compromised device.

The malware also uses the Solana blockchain as a mechanism for retrieving the address of a later command-and-control server. The blockchain account contains encoded infrastructure information that the malware can retrieve before connecting to the next stage.

Using a public blockchain does not make malicious infrastructure impossible to block, but it separates discovery of the current command server from the initial malware sample and places part of the coordination mechanism on infrastructure defenders cannot simply seize or remove.

The distribution model is equally significant. Reputation controls are less useful when malicious content is delivered through a service users and applications already expect to provide legitimate torrent files. Compromise of a shared upstream repository can also affect several downstream services at once.

For organisations, the campaign intersects with controls around unmanaged software and content rather than a conventional enterprise application vulnerability. Torrent clients, unofficial installers, cracked software, and user-supplied executables can introduce code outside established procurement and software-distribution processes, particularly where endpoints permit local execution or privilege elevation.

Kaspersky has not publicly named the affected organisations or attributed the campaign to a known criminal or state-backed group. The scale of enterprise impact beyond infected endpoints therefore remains unclear.

The repository remained compromised when Kaspersky published its technical research. That leaves the campaign as a continuing distribution problem rather than a retrospective malware analysis, while the absence of named victim disclosures means claims about organisational reach should remain tied to the company’s telemetry.

×