MovieReaper Framework Attacks via Compromised Torrent Repositories
Score: 8/10

MovieReaper Framework Attacks via Compromised Torrent Repositories

MovieReaper uses compromised torrent repositories and the Solana blockchain to deploy a multi-stage modular framework targeting diverse global sectors.

Executive Summary

In late 2026, researchers identified a large-scale infection campaign utilizing the 'MovieReaper' modular framework. The primary infection vector is a supply-chain-style compromise of the itorrents[.]org repository, which serves malicious torrent files to multiple trackers. This allows the threat actor to reach a massive audience of users downloading popular media without needing to compromise individual tracking sites directly.

Technically, MovieReaper is sophisticated, employing a four-stage infection chain. It features an initial loader that performs extensive anti-sandboxing checks, followed by a shellcode stage that retrieves second-stage C2 addresses from the Solana blockchain's data fields. This decentralized infrastructure makes traditional IP-based takedowns significantly more difficult. The final payload is a 'file manager' module capable of extensive exfiltration and system manipulation.

The campaign has broad geographic and sectoral reach, impacting individuals and organizations in Russia, Europe, Asia, and Africa. Targeted industries include government, IT, transportation, and retail. The modular nature of the framework suggests it is designed for long-term persistence and adaptability across future campaigns.

Key Details

Threat Name

MovieReaper

Affects

—

Adversary

MovieReaper

Malware/Tools

MovieReaper, file manager

Report Score

8out of 10
Quality Score
Good
IOC Quality9
TTP Details9
Detection Guidance5
Enterprise Relevance7
Clarity & Structure8
Technical Depth9

Sources