MovieReaper Malware Exploited Torrent Repositories

A malicious campaign active since October 2025 used compromised torrent links to deliver multi-stage malware globally.

Updated on Oct. 1, 2026 in Cybersecurity

Isometric editorial illustration of a decentralized lattice composed of matte geometric hexagonal pillars and block segments.
Researchers uncovered a malware campaign that compromised torrent repositories by injecting malicious loaders into file-sharing networks since October 2025. AI Illustration. Upload story photo >

Live Poll

Do you feel confident that your current cybersecurity habits protect you from torrent-based malware?

Researchers identified the MovieReaper malware campaign, which has been active since October 2025 by injecting malicious code into the itorrents[.]org repository. The campaign, discovered in mid-August 2026, has infected several hundred victims across multiple countries by disguising malware as legitimate movie downloads.

Why it matters

The use of the Solana blockchain for command-and-control communications demonstrates a shift toward decentralized infrastructure to harden malware against takedown efforts. This development forces users to contend with increasingly sophisticated delivery vectors in peer-to-peer file sharing.

The malware utilizes a multi-stage loader architecture to evade detection and relies on the Solana blockchain to dynamically fetch updated attacker server addresses. This replaces static hardcoded IP addresses, making the infrastructure significantly more resilient to standard network-level blocking.

The players

Kaspersky

A global cybersecurity firm that develops endpoint protection software, threat intelligence services, and malware analysis tools.

The details

The infection begins when users download files from itorrents[.]org, where attackers substituted legitimate magnet links—the digital fingerprints for downloading files via P2P networks—with malicious loaders. These loaders masquerade as movies using familiar application icons to induce user execution. Once triggered, the malware installs additional components in progressive stages, a technique designed to minimize the footprint of any single file and delay discovery by security software.

Timeline

  1. October 2025: Attacker activity was first traced.

  2. mid-August 2026: Researchers discovered the campaign.

  3. October 1, 2026: A report confirmed the repository remains compromised.

The Tech Race

The MovieReaper campaign reflects a broader trend of attackers targeting the distribution points of peer-to-peer networks to automate mass infections. This effort follows a pattern set by the compromise of the itorrents[.]org repository to bypass traditional security perimeters.

Users of file-sharing platforms face increased risk as attackers continue to weaponize trusted repositories and mask malicious payloads as media files. To mitigate risk, avoid downloading content from repositories that have exhibited irregular linking behavior or have been flagged in recent security audits.

The takeaway

The persistent compromise of large-scale repositories like itorrents[.]org indicates that attackers are successfully exploiting the trust users place in established file-sharing hubs. Keep watch for future security updates regarding the specific indicators of compromise linked to this campaign to ensure endpoint integrity.

Further reading

For more context on how threat actors manipulate digital distribution, explore our coverage of Cybersecurity.

Source note: This article includes information reported by Back End News.

Live Poll

Do you feel confident that your current cybersecurity habits protect you from torrent-based malware?