
A publicly available archive containing torrent files was altered to make magnet links provide some other file apart from what the user requested. This affected the trackers, which accessed the altered archive and provided the tricked users with the malware. The users who wanted to download a movie received a Windows executable file instead. It installed a multi-component implant dubbed MovieReaper.
Hundreds of compromised users were already detected. However, they are not all private users there are enterprises, governmental organizations, IT, consultancy, retail, transportation and agricultural firms on the list. Compromised machines are located in Russia, Türkiye, Japan, Spain, Germany, Finland, Nepal, Kenya, Tanzania, Ghana, Uganda, Colombia, the Netherlands and Belgium.
What is MovieReaper? MovieReaper is an advanced malware Windows framework distributed via compromised torrent files with popular movies. Its first component is the only one that hits the disk while other components operate in memory providing remote file system access for the attacker. The address of its C2 is stored in the Solana blockchain.
The Attackers Poisoned the Archive, Not the Trackers
There were no direct attacks against individual torrent websites. Instead, the attackers tampered with itorrents[.]org, which is a commonly used torrent file storage. As a result, all trackers using it started distributing malicious torrents without changing their own servers.
As you can see, just one compromise affected many websites’ users. This was true until the technical details were published on September 17. At this point, the magnet links were still providing a different torrent than what was requested.
The activity of the campaign was detected in mid-August 2026. It is still ongoing. However, the history of the attacker’s activities reaches back to October 2025.
A Long Filename Hiding an EXE
Stage one arrives as an executable named like a video file, for example the odyssey (2026) [1080p] [webrip] [5.1].exe. It carries the icon of a familiar application. Length pushes the real extension out of view. Across every download observed, the file hash stayed the same.
Nothing runs until the user double-clicks. That step is the whole of the social engineering. Guides for pirated software routinely instruct people to switch their antivirus off first.
Once started, the loader spends its effort on not being analyzed. A global mutex keeps one copy running, and a series of checks look for a sandbox. Windows functions are resolved by walking the loader list in the process environment block, never through LoadLibrary or GetProcAddress.
It then fetches shellcode from deadhub[.]org, falling back to a hardcoded IP address over plain HTTP if the domain fails. The download is split across URLs dressed up as interface images, sync-status-icons.png among them. Execution runs through EtwpCreateEtwThread, an undocumented alternative to the commonly monitored CreateThread.
A Pirated Download With an Unseizable Command Channel
The C2 Address Sits in a Blockchain Account
Stage two always lacks the server address. The request is sent to the Solana blockchain via a public RPC endpoint and retrieves data from an account. To decrypt it, the static XOR key stored in the shellcode needs to be used. This reveals the actual C2 address.
This information gets stored by operators through their own Solana smart contract. The account can’t be seized, and a takedown order can’t be served on it. Blocking the C2’s IP address will have little effect, as it will return whatever the operators set last.
All communication with the server occurs via HTTPS protocol using a pinned certificate and a minimalistic protobuf implementation. COFF object files get loaded in memory and run, so the modules aren’t saved on disk. Therefore, the command set can be extended without problems.
There is only one weak spot in this chain the loader. It relies on one domain name and the fallback IP address to load its shellcode. If this server goes down, everything after that, including the blockchain stage, stops working.
Persistence Dressed as a Microsoft Path
Stage three bypasses User Account Control, then reinstalls the binary as C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe and restarts it from there. That path reads like something Windows put there itself.
The restart carries a command-line argument that skips most of the anti-sandbox checks. A flag in the beacon reports whether the implant is running from the Telemetry folder. Operators can therefore tell a fresh infection from a respawn.
Twenty-One Commands Over the File System
The last module is a file manager. The manager provides access to 21 commands. Files can be downloaded, uploaded, viewed, created, duplicated, renamed, moved, deleted, symlinked and permissions changed, while directories can be enumerated.
There are two commands that allow to create previews and thumbnails. Users can view images and files to determine which files should be taken. In this way, operators ensure that the amount of stolen data is not too high and looks like regular network traffic.
Unknown Code the User Chose to Run
Every control in this chain was defeated by design. The loader checks whether it is inside a sandbox before doing anything interesting. Its later stages never touch disk. The C2 address lives somewhere no takedown reaches, and persistence hides inside a Microsoft-shaped path.
Detection answers one question about that executable: does it look malicious? A newly compiled loader with no history answers no.
Execution Governance asks whether the file is trusted instead. An executable downloaded through a torrent client has no trust verdict, whatever its icon or filename. On Windows endpoints, code in that state runs under Kernel API Virtualization. File system and registry writes are virtualized, so a binary copied into the Telemetry folder never gains the persistence it was aiming for. Network socket creation is denied, which stops the shellcode download, and the blockchain lookup never happens.
A loader that pulled its instructions from a smart contract came up in npm Supply Chain Malware Hides in Runtime Code, which we examined earlier. The delivery route differs here, and the reason for using a chain is identical: infrastructure that defenders cannot remove.
Conclusion: The Movie Was Fake. The Execution Was Real.
MovieReaper shows how a supply-chain compromise can turn ordinary user behavior into the final delivery step. Attackers did not need to breach every torrent tracker individually. By altering a shared torrent-file repository, they caused multiple sites to direct users toward malicious content while the surrounding download experience still appeared legitimate.
The final decision, however, happened on the endpoint. The downloaded file was not a movie but a Windows executable disguised through its filename and icon. Nothing malicious occurred until the user launched it. From that point, the loader fetched shellcode, resolved additional infrastructure through Solana, established persistence, and enabled later modules to operate largely in memory.
That sequence matters because the campaign deliberately removes many of the signals defenders normally depend on. Later stages avoid disk, the command infrastructure can change through a blockchain record, and persistence is placed under a Microsoft-looking path. Yet every sophisticated stage still depends on one much simpler event: an unknown executable being allowed to start and reach the network.
Why This Threat Matters
- One upstream compromise can affect many downstream sites. Poisoning a shared torrent repository expanded distribution without compromising each tracker separately.
- The first payload relies on deception, not an exploit. The user receives an executable presented as expected media and must launch it.
- Later stages minimize disk evidence. COFF modules can execute in memory, reducing the value of file-only detection.
- Blockchain infrastructure increases resilience. Operators can change the next C2 destination without replacing the malware or relying on a single attacker-owned domain.
- Consumer behavior reaches enterprise endpoints. Identified victims include government and commercial organizations, showing that risky personal downloads do not stay outside corporate environments.
Where Defensive Control Must Operate
Xcitium Advanced EDR, powered by Xcitium’s patented Zero-Dwell platform, provides the runtime visibility needed once the unknown loader starts, including follow-on execution, persistence, and suspicious network behavior.
Execution Governance addresses the earlier trust decision by restricting what an unverified executable is allowed to change or reach when it first runs.
Xcitium Cyber Awareness Education helps users recognize deceptive downloads and executable files disguised as expected media, while Phishing Simulation tests whether users resist the same type of deceptive link-and-launch scenario in practice.
Stop the Loader Before the Blockchain Matters
Defenders should not make the resilience of the later C2 infrastructure the primary problem. If the first unknown executable cannot establish network access, persistence, or trusted follow-on execution, the shellcode download and blockchain lookup never become relevant. Detection remains necessary for investigation, but the strongest control point appears before MovieReaper reaches its more sophisticated stages.