Security researchers have identified a modular, multi-stage malware framework named MovieReaper, which is being distributed through compromised torrent trackers. The campaign leverages the hijacking of the widely used public repository itorrents[.]org to replace legitimate torrent files with malicious loaders disguised as popular films. The infection chain is sophisticated, targeting a wide range of individual users and organizations across Europe, Asia, and Africa.
Technically, MovieReaper employs several advanced evasion techniques, including direct syscalls to bypass security software and a second-stage shellcode that utilizes the Solana blockchain to retrieve Command and Control (C2) server addresses. This decentralized approach makes the infrastructure highly resilient to takedown efforts. The final stage of the infection grants attackers comprehensive filesystem access, allowing for remote file manipulation and data exfiltration.
Top comments (0)