MovieReaper Malware Spreads Through Movie Torrents and Uses Solana for C2

Summary
Kaspersky details MovieReaper, a modular malware campaign that altered torrent files in the itorrents.org archive to infect users. The malware uses Solana to retrieve a second-stage C2 address and can remotely access victims’ files.
Key points
- Attackers modified the itorrents.org torrent archive, causing trackers that relied on it to distribute malicious torrent files disguised as popular movies.
- Kaspersky identified several hundred victims, including individuals and organizations across multiple countries; the archive remained compromised at publication.
- The loader downloads shellcode from deadhub[.]org, with 193.23.118[.]155 as a fallback, and uses anti-sandbox techniques.
- A later stage retrieves a second C2 address from data stored on the Solana blockchain, making that infrastructure harder to disrupt through conventional takedowns.
- The malware can bypass UAC, establish persistence, and load modular payloads; its final observed module supports remote file access and file manipulation.
- Kaspersky says disrupting the first-stage server could prevent subsequent infection stages and lists file hashes, paths, mutexes, domains, and IP addresses as indicators of compromise.
Article Details
- Attack Vectors
- An altered public torrent-file repository, itorrents[.]org, caused trackers relying on it to distribute malicious torrents in place of requested movie torrents.
- The malicious torrents delivered executable loaders disguised as movie files. Infection began when a user ran the downloaded executable.
- The loader downloaded shellcode from a first-stage C2 server and executed it in memory.
- The shellcode retrieved an encoded second-stage C2 address from a Solana account. Later modules performed UAC bypass, established persistence, and provided remote filesystem access.
- Defensive Notes
- Kaspersky products detect the threat as HEUR:Trojan.Win64.Agent.gen.
- The researchers identify the first-stage shellcode server as the clearest disruption point: its domain and fallback IP address are needed before subsequent infection stages can run.
- The report says the torrent archive remained compromised at publication.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | deadhub[.]org | First-stage C2 domain used by the loader to download shellcode. |
| DOMAIN | itorrents[.]org | Compromised torrent-file repository that distributed malicious torrents through trackers relying on it. |
| IPV4 | 193[.]23[.]118[.]155 | Fallback first-stage C2 IP address used to download shellcode. |
| IPV4 | 208[.]64[.]33[.]90 | Listed second-stage C2 IP address. |
| IPV4 | 208[.]94[.]246[.]53 | Listed second-stage C2 IP address. |
| MD5 | 4843f9fafcae492f11e2d4d33dbb4cdd | Malicious file hash listed in the indicators of compromise. |
| MD5 | 5310cabae3fbe6db8742849b588093f9 | Malicious file hash listed in the indicators of compromise. |
| MD5 | 70060341caf3338697a7ddfe0fb62875 | Malicious file hash listed in the indicators of compromise. |
| MD5 | a0b13781edd7cfdab13d79afff3c83c1 | Hash of a widely distributed executable loader disguised as a movie file. |
| MD5 | ad4643eea15ac286fa47d1131f9ef756 | Malicious file hash listed in the indicators of compromise. |
| MD5 | d0b967571ac8a3863c7f324bf5bde99c | Malicious file hash listed in the indicators of compromise. |
| MD5 | d88d550d0fb8e60cffff3ea61ff7a067 | Malicious file hash listed in the indicators of compromise. |
MITRE ATT&CK
T1005 · Data from Local SystemThe final module let the operator read and download files from the victim host.T1027 · Obfuscated Files or InformationThe malware encrypted strings with a custom stream cipher; the shellcode also held an XOR-encrypted C2 address.T1036.005 · Match Legitimate Resource Name or LocationFor persistence, the malware placed its executable at C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe, masquerading as msedge.exe.T1041 · Exfiltration Over C2 ChannelThe file-manager module could exfiltrate previews of images and files through its C2-controlled commands.T1083 · File and Directory DiscoveryThe final file-manager module let the operator list and enumerate directories on the victim host.T1102.001 · Dead Drop ResolverThe shellcode read a Solana account containing the encoded address of its next C2 server.T1105 · Ingress Tool TransferThe loader downloaded shellcode from the first-stage C2 server, and later stages downloaded additional modules.T1204.002 · Malicious FileInfection began when a user manually ran a downloaded executable disguised as a movie.T1548.002 · Bypass User Account ControlA third-stage module performed UAC bypass.T1620 · Reflective Code LoadingThe second-stage implant parsed a received COFF file, loaded it into memory, and executed its module_init function.
Malware
Vendors
Products
Countries
BelgiumKenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.Colombiausers and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.FinlandEurope, Asia, Africa, and Latin America, with infection attempts identified in Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana, Uganda, Colombia, the Netherlands, Belgium, and otherGermanyUganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.Ghanainfection attempts identified in Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana, Uganda, Colombia, the Netherlands, Belgium, and other countries.Japanincluding both individual users and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands,Kenyaincluding both individual users and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, andNepaland Latin America, with infection attempts identified in Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana, Uganda, Colombia, the Netherlands, Belgium, and other countries.Russiaseveral hundred victims, including both individual users and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, theSpainas Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.Tanzaniawith infection attempts identified in Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana, Uganda, Colombia, the Netherlands, Belgium, and other countries.the NetherlandsTürkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.Türkiyevictims, including both individual users and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, theUgandaboth individual users and organizations in multiple countries, such as Russia, Türkiye, Japan, Kenya, Uganda, and Colombia, as well as in several European countries like Spain, the Netherlands, Belgium, and Germany.
Industries
AgricultureThe targeted organizations span a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.ConsultingThe targeted organizations span a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.GovernmentThe targeted organizations span a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.ITThis approach is particularly dangerous because it lets the threat actor reach users of multiple trackers without having to compromise each platform individually.RetailThe targeted organizations span a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.TransportationThe targeted organizations span a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.