Windows users who downloaded movies through torrent sites may have received MovieReaper malware instead. The campaign has affected hundreds of individuals and organizations across several countries.
The malicious torrent delivered an executable disguised with a long movie-related name. One common example was “the odyssey (2026) [1080p] [webrip] [5.1].exe,” with the .exe ending potentially hidden from view by the filename’s length.
Its final file-management module gives a remote operator broad access to stored data. The attacker can browse folders, read, upload, download, rename, move or delete files, and preview selected content before stealing it.
The researchers suspect additional modules may be delivered when requested, but did not confirm what those other modules would do.
A shared torrent archive was compromised
Kaspersky researchers found that the attackers had not breached each torrent tracker. They instead compromised itorrents[.]org, a public repository used by multiple trackers, causing magnet-link requests to return a different, malicious torrent file.The malicious torrent delivered an executable disguised with a long movie-related name. One common example was “the odyssey (2026) [1080p] [webrip] [5.1].exe,” with the .exe ending potentially hidden from view by the filename’s length.
What MovieReaper can do
Once launched, MovieReaper downloads further stages and creates a persistent copy at C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. Persistence means the malware is set up to return after Windows restarts.Its final file-management module gives a remote operator broad access to stored data. The attacker can browse folders, read, upload, download, rename, move or delete files, and preview selected content before stealing it.
The researchers suspect additional modules may be delivered when requested, but did not confirm what those other modules would do.
Countries and organizations affected
Kaspersky observed infection attempts across Europe, Asia and Africa, including Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania and Ghana. Targets included home users as well as enterprise, government, IT, retail, transportation and agriculture organizations.What torrent users should check
- Run a full antivirus scan, particularly if you recently opened an .exe file presented as a movie. Kaspersky detects the threat as HEUR:Trojan.Win64.Agent.gen.
- Check for C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. Its presence is a reported indicator of this campaign; do not confuse it with legitimate Microsoft Edge files in their normal installation folders.
- Review security or network logs for contact with deadhub[.]org or 193.23.118[.]155, the first-stage command server indicators reported by the researchers.
- If you find an indicator, disconnect the PC from the network, quarantine the detected malware with your security software and change important passwords from a separate, clean device.

