MovieReaper Malware Spreads Through Movie Torrents and Uses Solana for C2

· Original article ↗

Summary

Kaspersky details MovieReaper, a modular malware campaign that altered torrent files in the itorrents.org archive to infect users. The malware uses Solana to retrieve a second-stage C2 address and can remotely access victims’ files.

Key points

  • Attackers modified the itorrents.org torrent archive, causing trackers that relied on it to distribute malicious torrent files disguised as popular movies.
  • Kaspersky identified several hundred victims, including individuals and organizations across multiple countries; the archive remained compromised at publication.
  • The loader downloads shellcode from deadhub[.]org, with 193.23.118[.]155 as a fallback, and uses anti-sandbox techniques.
  • A later stage retrieves a second C2 address from data stored on the Solana blockchain, making that infrastructure harder to disrupt through conventional takedowns.
  • The malware can bypass UAC, establish persistence, and load modular payloads; its final observed module supports remote file access and file manipulation.
  • Kaspersky says disrupting the first-stage server could prevent subsequent infection stages and lists file hashes, paths, mutexes, domains, and IP addresses as indicators of compromise.

Article Details

Attack Vectors
  • An altered public torrent-file repository, itorrents[.]org, caused trackers relying on it to distribute malicious torrents in place of requested movie torrents.
  • The malicious torrents delivered executable loaders disguised as movie files. Infection began when a user ran the downloaded executable.
  • The loader downloaded shellcode from a first-stage C2 server and executed it in memory.
  • The shellcode retrieved an encoded second-stage C2 address from a Solana account. Later modules performed UAC bypass, established persistence, and provided remote filesystem access.
Defensive Notes
  • Kaspersky products detect the threat as HEUR:Trojan.Win64.Agent.gen.
  • The researchers identify the first-stage shellcode server as the clearest disruption point: its domain and fallback IP address are needed before subsequent infection stages can run.
  • The report says the torrent archive remained compromised at publication.

Indicators of compromise

TypeIndicatorContext
DOMAINdeadhub[.]orgFirst-stage C2 domain used by the loader to download shellcode.
DOMAINitorrents[.]orgCompromised torrent-file repository that distributed malicious torrents through trackers relying on it.
IPV4193[.]23[.]118[.]155Fallback first-stage C2 IP address used to download shellcode.
IPV4208[.]64[.]33[.]90Listed second-stage C2 IP address.
IPV4208[.]94[.]246[.]53Listed second-stage C2 IP address.
MD54843f9fafcae492f11e2d4d33dbb4cddMalicious file hash listed in the indicators of compromise.
MD55310cabae3fbe6db8742849b588093f9Malicious file hash listed in the indicators of compromise.
MD570060341caf3338697a7ddfe0fb62875Malicious file hash listed in the indicators of compromise.
MD5a0b13781edd7cfdab13d79afff3c83c1Hash of a widely distributed executable loader disguised as a movie file.
MD5ad4643eea15ac286fa47d1131f9ef756Malicious file hash listed in the indicators of compromise.
MD5d0b967571ac8a3863c7f324bf5bde99cMalicious file hash listed in the indicators of compromise.
MD5d88d550d0fb8e60cffff3ea61ff7a067Malicious file hash listed in the indicators of compromise.

MITRE ATT&CK

Malware

Vendors

Products

Countries

BelgiumKenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.Colombiausers and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.FinlandEurope, Asia, Africa, and Latin America, with infection attempts identified in Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana, Uganda, Colombia, the Netherlands, Belgium, and otherGermanyUganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.Ghanainfection attempts identified in Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana, Uganda, Colombia, the Netherlands, Belgium, and other countries.Japanincluding both individual users and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands,Kenyaincluding both individual users and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, andNepaland Latin America, with infection attempts identified in Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana, Uganda, Colombia, the Netherlands, Belgium, and other countries.Russiaseveral hundred victims, including both individual users and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, theSpainas Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.Tanzaniawith infection attempts identified in Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana, Uganda, Colombia, the Netherlands, Belgium, and other countries.the NetherlandsTürkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.Türkiyevictims, including both individual users and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, theUgandaboth individual users and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.

Industries

Related Articles