VYPR
malwarePublished Sep 17, 2026· 1 source

MovieReaper Malware Spreads via Compromised Torrents, Targets Global Users

A new modular malware framework named MovieReaper is being distributed through compromised torrent files, masquerading as popular movies and infecting users worldwide.

Cybercriminals are once again leveraging the widespread appeal of torrents to distribute malicious software, this time through a sophisticated new framework dubbed MovieReaper. Threat actors have successfully compromised a popular public repository of torrent files, leading numerous torrent trackers to inadvertently distribute malicious loaders disguised as popular movies. This tactic exploits user behavior, as installation guides for pirated software often instruct users to disable antivirus protection, making them more susceptible to malware.

The MovieReaper campaign began in mid-August 2026, with researchers identifying a large-scale infection campaign affecting both individual users and organizations across numerous countries, including Russia, Türkiye, Japan, Kenya, Uganda, Colombia, Spain, the Netherlands, Belgium, and Germany. The malware employs a multi-stage infection chain and custom encryption techniques designed to evade detection by security solutions and sandboxes.

The initial infection vector is particularly insidious. Instead of compromising the torrent trackers directly, the attackers compromised a widely used public torrent file repository. This allowed them to distribute malicious torrent files to users across multiple trackers simultaneously without needing to breach each platform individually. When a user attempts to download a torrent, the legitimate archive returns a malicious file that initiates the malware loader.

The loader executable, often disguised with long filenames and familiar application icons to hide its true nature, establishes a global mutex to prevent multiple instances from running. It then performs a series of checks to evade AV sandbox detection, notably avoiding standard API calls for function acquisition. Instead, it manually parses loaded DLLs to calculate function addresses, a technique aimed at bypassing common detection mechanisms.

Once these checks are passed, the loader attempts to connect to a command-and-control (C2) web server, using a primary domain and a fallback IP address. It downloads shellcode in parts, requesting specific file paths that mimic legitimate cloud service requests. This obfuscation helps the malware blend in with normal network traffic.

Further evasion techniques are employed during the execution of the shellcode. The loader registers a vectored exception handler and modifies its address in memory. This allows it to perform a debug break that redirects control flow to a function capable of making raw system calls for memory protection, bypassing standard Windows API calls.

Kaspersky products detect this threat as HEUR:Trojan.Win64.Agent.gen. The modular nature of MovieReaper suggests a flexible and potentially evolving threat. While the initial loader and shellcode are designed for stealth and evasion, the framework's modularity implies it could be used to deploy a variety of malicious payloads, making it a significant concern for cybersecurity professionals.

This campaign highlights the persistent threat posed by torrent-based malware distribution and the increasing sophistication of malware frameworks designed to evade modern security defenses. The use of custom encryption and advanced evasion techniques underscores the need for robust endpoint protection and continuous threat intelligence.

Synthesized by Vypr AI
MovieReaper Malware Spreads via Compromised Torrents, Targets Global Users · VYPR