Cybersecurity company Kaspersky has identified several hundred victims of MovieReaper, a malware campaign that disguises harmful software as popular movie downloads. The infections affected individuals and organizations across multiple countries after attackers compromised a shared repository used by torrent websites.
The attack shows how tampering with one service can spread malicious downloads across several platforms. Affected organizations span government, IT, consulting, retail, transportation, agriculture, and other business sectors.
Researchers discovered the campaign in mid-August 2026 while investigating malware that uses blockchain networks to support communications with attackers. Victims had one common link: They had used torrent trackers to download content.
Further investigation found that attackers had modified itorrents[.]org, a widely used public repository of torrent files. Torrent files contain information that helps download software locate and retrieve the requested content.
Websites relying on the repository then unknowingly distributed malicious torrent files. This allowed attackers to reach users of multiple torrent trackers without breaking into each website separately.
According to the report, the repository remained compromised at publication. Attempts to retrieve a torrent through a magnet link could return a substituted file that directs users to download the MovieReaper malware loader.
The loader is a program that starts the infection and installs additional malicious components. Attackers disguised these programs with movie titles, long filenames, and familiar application icons. Researchers said the long names presumably helped conceal the “.exe” ending, which identifies a Windows executable rather than a video.
MovieReaper installs its components in stages, with later parts running in computer memory to reduce detection. It also uses techniques designed to avoid automated security systems that examine suspicious files.
The campaign uses the legitimate Solana blockchain to deliver the address of a server controlled by attackers. Storing this information on a decentralized network makes the campaign harder to disrupt simply by blocking server addresses.
However, researchers identified a weakness in the first infection stage: It depends on one domain name and one IP address to deliver malicious code. Taking that server offline would prevent subsequent infection stages.
Infection attempts were observed in Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana, Uganda, Colombia, the Netherlands, Belgium, and other countries.
Kaspersky traced activity by the same attacker to October 2025. Researchers said MovieReaper’s structure allows its components to be reused in future campaigns with limited changes, extending the threat beyond the current wave of infected movie downloads.
Image from Kaspersky

