A previously unknown Windows Trojan, which spreads through the download of pirated movies, has been discovered. This malicious code has infected hundreds of users and organizations across Europe, Asia, and Africa. It utilizes the Solana blockchain to ensure that its command infrastructure is inaccessible to standard threat remediation measures.
A new type of threat
The global research and analysis team at Kaspersky named this malware MovieReaper and published their analysis on the Securelist platform late last week. Affected entities include companies from the enterprise, public administration, IT, consulting, retail, transport, and agriculture sectors. Infections have been recorded in African countries such as Kenya, Tanzania, and Ghana; South Africa is not among the affected nations.
The method of propagation is particularly noteworthy. Instead of attacking torrent sites individually, the attackers compromised itorrents.org—a public repository of torrent files used by numerous trackers. A user clicking on a magnet link on a legitimate tracker could receive an entirely different torrent file leading to the malware downloader. Kaspersky reported that the repository remained under the control of the attackers at the time of publication.
One sample had the long name 'the odyssey (2026) [1080p] [webrip] [5.1].exe', likely done to conceal the .exe extension. Nevertheless, manual user intervention was required to run the file. After execution, the downloader first checks if it is running in an antivirus sandbox, and then retrieves shellcode from one domain—deadhub.org, with the option to switch to a hardcoded IP address via unencrypted HTTP protocol in case of failure.
In the second stage, the malware contacts the Solana blockchain to determine the next reporting point. It reads an account on the network controlled by the attackers, which contains an encrypted address of the second command server. Since this address resides on a public blockchain rather than in a domain name system, it cannot be removed by seizing a domain or blacklisting an IP address.
Full remote access
Subsequently, the malware bypasses Windows user account controls, gaining administrator privileges without a standard prompt. It installs itself as msedge.exe in the Telemetry folder within ProgramData and downloads the final module, which Kaspersky describes as a file manager with twenty-one commands. These commands allow the operator to browse directories, read, copy, move, rename, and delete files, as well as retrieve thumbnails and previews of documents and images before deciding what to steal.
This grants full remote access to everything the infected machine can reach. For anyone who downloaded a movie on a work laptop or a personal device connected to a corporate network, this could mean much more than just the computer itself. Kaspersky noted that the first stage provides the most obvious opportunity to interrupt the campaign, as it depends on a single domain and a single IP address, whereas subsequent stages are harder to track. The practical advice offered by the research to network defenders is to monitor or block access to public blockchain endpoints from corporate networks where it is not required for a legitimate application. The company identifies the malware as HEUR:Trojan.Win64.Agent.gen and published file hashes, paths, and command server addresses that security services can use to check their own environments. Researchers traced the activity of the same actor back to October 2025.
