Executive Summary
In late 2026, researchers identified a large-scale infection campaign utilizing the 'MovieReaper' modular framework. The primary infection vector is a supply-chain-style compromise of the itorrents[.]org repository, which serves malicious torrent files to multiple trackers. This allows the threat actor to reach a massive audience of users downloading popular media without needing to compromise individual tracking sites directly.
Technically, MovieReaper is sophisticated, employing a four-stage infection chain. It features an initial loader that performs extensive anti-sandboxing checks, followed by a shellcode stage that retrieves second-stage C2 addresses from the Solana blockchain's data fields. This decentralized infrastructure makes traditional IP-based takedowns significantly more difficult. The final payload is a 'file manager' module capable of extensive exfiltration and system manipulation.
The campaign has broad geographic and sectoral reach, impacting individuals and organizations in Russia, Europe, Asia, and Africa. Targeted industries include government, IT, transportation, and retail. The modular nature of the framework suggests it is designed for long-term persistence and adaptability across future campaigns.
