MalwareTips News MovieReaper malware spreads through movie torrents and gives attackers access to files

Security News
10 Replies 675 Views

Do you check a downloaded file’s type before opening it?

  • Always

    Votes: 8 72.7%
  • Only when it looks suspicious

    Votes: 2 18.2%
  • Rarely

    Votes: 1 9.1%
  • I am not sure

    Votes: 0 0.0%

  • Total voters
    11

News Now

Happening Now
Verified
Windows users who downloaded movies through torrent sites may have received MovieReaper malware instead. The campaign has affected hundreds of individuals and organizations across several countries.


A shared torrent archive was compromised​

Kaspersky researchers found that the attackers had not breached each torrent tracker. They instead compromised itorrents[.]org, a public repository used by multiple trackers, causing magnet-link requests to return a different, malicious torrent file.

The malicious torrent delivered an executable disguised with a long movie-related name. One common example was “the odyssey (2026) [1080p] [webrip] [5.1].exe,” with the .exe ending potentially hidden from view by the filename’s length.

What MovieReaper can do​

Once launched, MovieReaper downloads further stages and creates a persistent copy at C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. Persistence means the malware is set up to return after Windows restarts.

Its final file-management module gives a remote operator broad access to stored data. The attacker can browse folders, read, upload, download, rename, move or delete files, and preview selected content before stealing it.

The researchers suspect additional modules may be delivered when requested, but did not confirm what those other modules would do.

Countries and organizations affected​

Kaspersky observed infection attempts across Europe, Asia and Africa, including Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania and Ghana. Targets included home users as well as enterprise, government, IT, retail, transportation and agriculture organizations.

What torrent users should check​

  • Run a full antivirus scan, particularly if you recently opened an .exe file presented as a movie. Kaspersky detects the threat as HEUR:Trojan.Win64.Agent.gen.
  • Check for C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. Its presence is a reported indicator of this campaign; do not confuse it with legitimate Microsoft Edge files in their normal installation folders.
  • Review security or network logs for contact with deadhub[.]org or 193.23.118[.]155, the first-stage command server indicators reported by the researchers.
  • If you find an indicator, disconnect the PC from the network, quarantine the detected malware with your security software and change important passwords from a separate, clean device.
 
I use Total Commander as my file manager so I always see files' extensions.
I also download movies from private tracker and so far never got a torrent with fake content.

Though ordinary users, with hidden file extensions (MS when will you change this dangerous default?) could easily execute malware, hidden that way.
 
I use Total Commander as my file manager so I always see files' extensions.
I also download movies from private tracker and so far never got a torrent with fake content.

Though ordinary users, with hidden file extensions (MS when will you change this dangerous default?) could easily execute malware, hidden that way.
Maybe because files/icons/etc are more presentable without the extensions.
But security wise, it's very prone to double extensions.
 
I use Total Commander as my file manager so I always see files' extensions.
I also download movies from private tracker and so far never got a torrent with fake content.

Though ordinary users, with hidden file extensions (MS when will you change this dangerous default?) could easily execute malware, hidden that way.
This is why you have never seen this attack. Private trackers = good with active mods & users reporting bad torrents. Public trackers = BAD and a free for all.

I've had almost tracker available and by far the worst culprit is music production trackers VST's & DAWs. Just full of malware even on legit trackers.

I remember back in the day downloading malicious VSTs that basically had your PC running to a crawl because all the malware and bots were fighting over resources.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top