Fake Movie Torrent Drops MovieReaper Trojan

Securelist · High sophistication
Last updated September 17, 2026

A real malware campaign dubbed “MovieReaper” infected users who tried to download popular movies from torrent trackers. Attackers abused a compromised public torrent-file repository so that magnet links returned a different torrent that downloaded a Windows .exe disguised as a movie file, which users then ran manually.

Key findings

  • Attackers distributed a Windows executable disguised as a movie download (e.g., a 1080p “WEBRIP” file) and relied on the user to run it.
  • The distribution scale came from compromising a public torrent-file repository (itorrents[.]org), which then affected multiple torrent trackers that depended on it.
  • The malicious torrent led to a loader that fetched additional payloads from a first-stage C2 domain/IP and later used Solana blockchain to retrieve next-stage C2 addresses.
  • The malware established persistence by masquerading as a Microsoft telemetry/Edge binary at %ProgramData%\Microsoft\Windows\Telemetry\msedge.exe.

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Security awareness training audience, Employees who download software/media, Helpdesk (handling suspected malware reports).
  • Affected industries: Individuals/consumers, Government, IT, Consulting, Retail, Transportation, Agriculture, Enterprise (multiple sectors).
  • Attack channels: website.
  • Impersonated: Torrent tracker / torrent file repository, Public torrent file repository (itorrents[.]org).

Awareness takeaways

  • Treat “movie/game downloads” that are actually .exe files as a likely attack and do not run them.
  • Do not disable antivirus or ignore warnings just to install or open untrusted downloads.
  • Block/monitor known bad domains and IPs quickly, early-stage infrastructure disruption can stop the infection chain.
  • Be aware attackers may use legitimate services (like blockchain APIs) to make takedowns harder, so detection should not rely only on blocking IPs.

Red flags to watch for

  • The download is an .exe application instead of a video file (e.g., .mp4/.mkv)
  • A very long filename appears designed to hide the “.exe” extension
  • Untrusted content is obtained from torrent sites/repositories
  • Unexpected content returned for a known magnet link
  • Multiple users report suspicious downloads for the same content
  • Downloads originate from an untrusted third-party repository
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You grab a torrent for a new movie… but the “movie file” is actually a Windows app called the odyssey (2026) [1080p] [webrip] [5.1].exe. In the real MovieReaper campaign, attackers compromised a torrent-file repository called itorrents.org, so magnet links quietly returned a different torrent that dropped this fake movie installer. When you run it, MovieReaper installs itself as msedge.exe under ProgramData\Microsoft\Windows\Telemetry, phones home to a first-stage server, then even uses the Solana blockchain to look up its next control servers. Aha moment: real movies are .mp4 or .mkv, not .exe. If your “movie” download ends in .exe, stop. Don’t run it, report it to Security immediately.

Similar attacks

Fake Download Sites Push Malware Installers

Fake Download Sites Push Malware Installers

Microsoft reports an active campaign where attackers set up counterfeit software download pages that mimic well-known brands and trick users into installing malware. Victims visit a look-alike vendor site, click “Download now,” then run a bundled installer that drops persistent malware and connects…

September 2, 2026
AI “Vibe Coding” Fuels Fake Package Trap

AI “Vibe Coding” Fuels Fake Package Trap

An active campaign (“Phantom Raven”) targets developers by exploiting AI coding assistants that suggest non-existent package names. Attackers register those hallucinated names in public repositories and plant malicious code so that automated installs can quietly introduce malware into build…

August 25, 2026
Spear-Phishing RTF Hits Bangladesh Defense Targets

Spear-Phishing RTF Hits Bangladesh Defense Targets

Researchers reported a targeted espionage operation against Bangladesh’s military and defense organizations using spear‑phishing emails with a booby‑trapped RTF document. When opened, the file pulls malicious content remotely and installs an implant that persists on the device while quietly sending…

July 17, 2026
Fake Zoom/Webex Installers Drop Starland RAT

Fake Zoom/Webex Installers Drop Starland RAT

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools like Zoom, Webex, and MobaXterm. Victims are socially engineered via a “ClickFix” style trick into running a command that silently…

July 17, 2026
Phishers Hide Lua Malware as “.TTF Font”

Phishers Hide Lua Malware as “.TTF Font”

A real, ongoing phishing campaign is tricking recipients into opening malicious archives that appear to contain harmless TrueType font files (.ttf) but actually hide a Lua-based loader. Once executed, the loader uses stealthy, mostly in-memory techniques to install remote access trojans and…

July 16, 2026
Fake Minecraft Sites Keep Spreading WeedHack

Fake Minecraft Sites Keep Spreading WeedHack

Attackers are tricking Minecraft players into downloading malware by cloning legitimate mod/client websites and manipulating search results so the malicious pages appear highly ranked. Even after the malware’s command-and-control systems were disrupted, the fake sites and trusted file-hosting links…

September 8, 2026