// 1 CRITICAL · 2 ZERO-DAY · 2 CVE IN THE LAST 24H→
On September 21, 2026, Kaspersky GReAT disclosed a multi-stage campaign active since at least mid-August and still ongoing. The MovieReaper operation exploits the compromise of the itorrents[.]org torrent repository to distribute a previously unknown malware framework, with several hundred confirmed victims across at least ten countries and critical sectors including government, IT, and transportation. The real target is not the individual downloading pirated movies, but the corporate infrastructure those same users reach with underestimated devices.
{"main_topic":"malware","topics":["malware","cybersecurity","enterprise","blockchain","supply-chain"]}

On September 21, 2026, Kaspersky GReAT disclosed a multi-stage campaign active since at least mid-August and still ongoing. The MovieReaper operation exploits the compromise of the itorrents[.]org torrent repository to distribute a previously unknown malware framework, with several hundred confirmed victims across at least ten countries and critical sectors including government, IT, and transportation. The real target is not the individual downloading pirated movies, but the corporate infrastructure those same users reach with underestimated devices.

Key Takeaways
  • Kaspersky GReAT identified the MovieReaper framework, a multi-stage strain distributed via torrents disguised as popular films such as The Odyssey
  • The itorrents[.]org repository is compromised and distributes altered torrent files to multiple dependent trackers, amplifying reach without attacking each platform individually
  • The malware uses the Solana blockchain to resolve command-and-control server addresses, making the infrastructure resistant to traditional takedowns
  • Confirmed victims include organizations in enterprise, government, IT, consulting, retail, transportation, and agriculture, with confirmed infections in Russia, Turkey, Japan, Kenya, Uganda, Colombia, Spain, the Netherlands, Belgium, and Germany

How the Attack Works: The Torrent Supply Chain

Kaspersky GReAT researchers documented an infection mechanism that inverts the classic torrent malware paradigm. Instead of uploading malicious files to individual trackers, the threat actor compromised itorrents[.]org, a widely used public archive of torrent files. Trackers dependent on this repository began automatically distributing altered torrents to their users.

This architecture is particularly efficient because it multiplies by induction: a single point of compromise generates infections across multiple platforms without the attacker needing to manage separate accesses. According to the Securelist technical report, the repository "remains compromised as of the report's publication date." When a user attempts to download a torrent via magnet link, the archive returns a torrent file different from the legitimate one.

The initial executable was distributed under different names but with an identical hash: MD5 A0B13781EDD7CFDAB13D79AFFF3C83C1. A documented example is 'the odyssey (2026) [1080p] [webrip] [5.1].exe'. Kaspersky detects this threat as HEUR:Trojan.Win64.Agent.gen.

The Framework: Evasion, Persistence, and Escalation

MovieReaper is structured as a modular framework with at least three identified functional components. The initial loader performs environmental detection to evade antivirus sandboxes: it executes specific operations to determine whether the execution environment is an automated analysis system. If the check passes the evasion phase, the framework proceeds with installation of subsequent modules.

Confirmed modules include: persistence surviving system reboot, UAC (User Account Control) bypass to gain administrative privileges, and a module for remote access to the compromised device. The report does not specify the final payload actually executed after full installation: the campaign's ultimate objective — data theft, espionage, or ransomware deployment — remains undeclared by the source.

"Instead of compromising torrent trackers, the threat actor modified a widely used public repository of torrent files, itorrents[.]org. As a result, the trackers that relied on the repository began inadvertently distributing malicious torrent files to their users. This approach is particularly powerful because it lets the threat actor reach users of multiple trackers without having to compromise each platform individually." — Kaspersky GReAT, Securelist technical report

C2 on Solana Blockchain: An Architecture Hard to Take Down

A distinctive element of MovieReaper is the use of the Solana blockchain for resolving command-and-control server addresses. The malware contains no hardcoded C2 addresses and does not rely on domains registrable via traditional DNS: it retrieves the C2 server address by querying the blockchain.

This architectural choice has concrete operational consequences for defenders. Traditional takedown techniques — domain seizure, registrar requests, DNS sinkholing — lose effectiveness against infrastructure that lives on a distributed, immutable ledger. The source does not specify the smart contract address or the exact resolution method, but the general logic is clear: the attacker can update C2 pointing by modifying on-chain data, while authorities must contend with a decentralized network lacking a central suppression authority.

What to Do Now

  • Verify that corporate devices do not run torrent clients or unauthorized P2P download software: the compromise of itorrents[.]org is active and the risk of infection via altered torrents is immediate
  • Isolate and analyze any endpoints that downloaded files from torrent trackers since August 15, 2026, with particular attention to known hashes published by Kaspersky
  • Review internet access policies and proxy/web filtering rules to block traffic to known torrent domains, including those dependent on centralized repositories
  • Evaluate implementation of network controls capable of detecting anomalous communications to Solana RPC endpoints or suspicious blockchain query patterns from unauthorized workstations

Who It Targets and Why the Profile Is More Dangerous Than Usual

Victim demographics refute the conventional narrative of torrent malware as an exclusively consumer threat. Confirmed organizations operate across eight sectors: enterprise, government, IT, consulting, retail, transportation, and agriculture. Geographic distribution spans Europe, Asia, Africa, and South America, with documented but not exclusive concentration in emerging markets.

The risk profile shifts when the infected device is a corporate laptop, a workstation with VPN access, or a machine with cached domain credentials. MovieReaper's modular framework — with persistence, privilege escalation, and remote access — is designed for lateral movement, not simple theft of home-user banking data. The absence of confirmation on the final payload does not diminish this assessment: the installed capabilities are compatible with persistent access operations and intelligence gathering.

The enterprise angle demands a specific reading. Companies monitoring only "traditional" threats — corporate phishing, VPN vulnerabilities, malicious attachments — risk underestimating the informal perimeter constituted by employee behavior on hybrid devices. MovieReaper demonstrates that a consumer repository can become a supply-chain attack vehicle against institutional targets.

Frequently Asked Questions

Has the itorrents[.]org repository been cleaned up?
According to the Kaspersky report published September 21, 2026, the archive "remains compromised." The source neither reports nor confirms corrective actions by the service operator.

Could other films besides The Odyssey be used as lures?
The report documents the loader with identical hash distributed under different filenames, but does not provide an exhaustive list of titles used. The attack logic — exploiting demand for popular films — suggests high-search-volume titles are most probable, but this aspect is not detailed in the source.

Is MovieReaper linked to the Argamal campaign previously documented by Kaspersky?
Kaspersky also published a 2026 report on Argamal, malware distributed via adult games with partially overlapping techniques. The dossier neither confirms nor denies a correlation between the two campaigns: threat actor, infrastructure, and objectives remain unconnected entities in available sources.

Information has been verified against cited sources and updated at time of publication.

Sources


Sources and references
  1. darkreading.com
  2. pctechmag.com
  3. brandspurng.com
  4. brandiconimage.com
  5. vftt.co.za
  6. freshangleng.com
  7. kaspersky.com
  8. securelist.com
  9. r.news.africa-newsroom.com