MovieReaper Malware Infected Users Through Torrent Files

Researchers identified a widespread campaign that compromised a popular torrent repository to spread malicious software.

Updated on Oct. 1, 2026 in Cybersecurity

Isometric editorial illustration of interconnected hexagonal metallic nodes forming a decentralized structural chain, representing a blockchain-based malware command system.
The MovieReaper malware campaign compromised the itorrents repository, utilizing decentralized Solana blockchain servers to maintain long-term control over infected user and business systems. AI Illustration. Upload story photo >

Live Poll

Do you feel confident that your current cybersecurity habits protect you from torrent-based malware?

Beginning in October 2025, the MovieReaper malware campaign targeted individuals and businesses by disguising malicious loaders as movie downloads. Researchers discovered the operation in mid-August 2026 after attackers compromised the itorrents[.]org repository.

Why it matters

The attackers utilized the Solana blockchain to manage command servers, creating a decentralized and resilient communication channel that is difficult to disrupt. This method highlights an evolving trend where threat actors leverage blockchain technology to ensure persistent control over infected systems.

The MovieReaper malware uses a multi-stage loading process designed to evade security detection while disguised as common movie files. It relies on a single domain and IP address for the initial infection stage before utilizing the Solana blockchain for command directives.

The players

Kaspersky

Kaspersky is a global cybersecurity and anti-virus provider that conducts threat intelligence research and incident analysis.

The details

Attackers surreptitiously modified the itorrents[.]org repository to replace legitimate magnet links with malicious loaders. Once executed, the software installs secondary components in phases to maintain a low profile within the host's operating system.

Timeline

  1. Attacker activity for the MovieReaper campaign was first traced in October 2025.

  2. Security researchers officially discovered the campaign in mid-August 2026.

  3. A formal report confirming that the repository remained compromised was published on October 1, 2026.

The Tech Race

The use of the Solana blockchain to manage command servers marks a departure from traditional centralized server-based malware control. This shift signals an arms race where attackers adopt decentralized ledger technologies to bypass conventional firewall and DNS-based blocking.

Users who download media files from torrent repositories face an increased risk of system compromise through disguised executables. To mitigate these threats, individuals should verify file extensions and maintain updated endpoint security software to detect multi-stage malware loaders.

The takeaway

The campaign demonstrates that even trusted file-sharing repositories can be weaponized to distribute sophisticated threats. Users should exercise caution when downloading content and rely on official distribution channels whenever possible.

Further reading

For more information on current global digital threats, visit the Cybersecurity section.

Source note: This article includes information reported by Back End News.

Live Poll

Do you feel confident that your current cybersecurity habits protect you from torrent-based malware?