MovieReaper: a modular crimeware framework distributed via a torrent-file-repository supply-chain compromise, using the Solana blockchain as a C2 dead-drop resolver
Kaspersky: a single compromised torrent-file repository silently poisoned magnet-link resolutions across many unrelated tracker sites
Analysis
Kaspersky documents MovieReaper, a previously undocumented modular Windows crimeware framework active since at least October 2025, distributed through a supply-chain compromise of itorrents.org (a shared public repository many independent torrent trackers rely on to resolve magnet links) rather than trojanized installers on individual sites, so a single compromise reaches users across many unrelated tracker sites simultaneously (Kaspersky Securelist, 2026-09-17). Several hundred victims are confirmed across enterprise, government, IT, consulting, retail, transportation and agriculture sectors, spanning Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania, Ghana and others across Europe, Asia and Africa (Kaspersky Securelist, 2026-09-17). After a user manually runs a first-stage loader disguised under a film-referencing filename, the loader resolves Windows API addresses by manually walking the PEB's loaded-module list rather than calling LoadLibrary or GetProcAddress, then registers a vectored exception handler that triggers a deliberate debug break to redirect control flow into a manually located raw syscall instruction inside ntdll and call NtProtectVirtualMemory directly, before invoking the undocumented ntdll export EtwpCreateEtwThread, which Kaspersky describes as a popular alternative to CreateThread, to execute the mapped shellcode (Kaspersky Securelist, 2026-09-17). The second stage queries the legitimate Solana blockchain's public getAccountInfo RPC endpoint to retrieve an XOR-encrypted C2 address, a dead-drop pattern that lets operators rotate infrastructure without touching the malware itself. A third stage performs a UAC bypass and persistence, masquerades as a Windows Telemetry executable, and hands off to a final remote-file-manager module exposing 21 filesystem commands, including preview commands Kaspersky reads as built for pre-exfiltration triage of image and document contents.
Cited evidence
we have discovered a previously unknown modular, multi-stage framework that we dubbed MovieReaper
the threat actors did not compromise the torrent trackers themselves. Instead, they compromised a widely used public repository of torrent files
By using Solana blockchain network as a distribution layer of endpoints for a next stage attackers may increase stability of their campaign and resist takedown efforts of defenders.
Sources1
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.