MovieReaper malware distributed via compromised torrent files targeting global users
The MovieReaper campaign is a multi-stage malware operation that uses compromised torrent files to distribute a modular framework. The malware employs HTTP and blockchain-based C2 infrastructure, including the Solana blockchain, to maintain persistence and evade detection. It has infected users across multiple countries, including Russia, Spain, and Germany, and has been active since at least October 2025. The campaign's use of the Solana blockchain for C2 communication adds a layer of resilience against takedown efforts.
- First seen
- 2025-10-01
- Last seen
- 2026-09-17
- Threat actors
- —
- Malware
- MovieReaper, HEUR:Trojan.Win64.Agent.gen
- Sectors
- Government, Defense, Financial Services, Healthcare, Energy, Telecommunications, Technology, Manufacturing, Retail, Transportation, Education, Legal
- Countries
- Russia, Turkey, Japan, Kenya, UG, Colombia, Spain, Netherlands, Belgium, Germany
How it works
The campaign begins with the distribution of malware via compromised torrent files. The loader establishes a global mutex and avoids detection by AV sandboxes. It then connects to a C2 server, either through the domain deadhub.org or a fallback IP address. The malware uses the Solana blockchain to retrieve the address of a second-stage C2 server. The second stage communicates via HTTPS with TLS-pinned certificates and uses the nanopb protobuf library. Stage 3 performs a UAC bypass and achieves persistence by masquerading as a legitimate Windows telemetry process. The final module provides the attacker with filesystem access on the victim host.
Techniques (MITRE ATT&CK)
- T1190 · initial_accessExploit Public-Facing ApplicationCompromised torrent trackers are the primary vector used to distribute malware.
- T1059.001 · executionPowerShellThe malware itself is not heavily obfuscated, apart from the fact that strings are encrypted with a custom stream cipher.
- T1040 · credential_accessNetwork SniffingStage 3 performs UAC Bypass and achieves persistence using public techniques.
- T1573.001 · command_and_controlSymmetric CryptographyLoader decodes https://deadhub[.]org domain name and if connection to it has failed, then it uses the IP address http://193.23.118[.]155 as a fallback and connects to it using plain HTTP.
- T1041 · exfiltrationExfiltration Over C2 ChannelThe final module ('file manager') exposes 21 commands that give the operator filesystem access on the victim host.
Indicators
Indicators associated with this campaign in the sources we reviewed. Corroborate before blocking: an address or domain can be shared infrastructure.
- A0B13781EDD7CFDAB13D79AFFF3C83C1
- deadhub.org
- api.mainnet.solana.com
What to do
- Block the C2 domains deadhub.org and api.mainnet.solana.com in network firewalls.
- Monitor for the presence of the MovieReaper loader file hash (A0B13781EDD7CFDAB13D79AFFF3C83C1) on endpoints.
- Implement network monitoring to detect traffic to the Solana blockchain RPC endpoint (api.mainnet.solana.com).
- Review and update endpoint detection and response (EDR) systems to identify and block the MovieReaper loader and associated malware modules.
- Educate users on the risks of downloading torrent files from untrusted sources and the importance of using legitimate software distribution channels.