MalwareTips News MovieReaper malware spreads through movie torrents and gives attackers access to files

Do you check a downloaded file’s type before opening it?

  • Always

    Votes: 7 87.5%
  • Only when it looks suspicious

    Votes: 0 0.0%
  • Rarely

    Votes: 1 12.5%
  • I am not sure

    Votes: 0 0.0%

  • Total voters
    8

News Now

Happening Now
Thread author
Verified
Sep 8, 2026
20
56
1
Windows users who downloaded movies through torrent sites may have received MovieReaper malware instead. The campaign has affected hundreds of individuals and organizations across several countries.


A shared torrent archive was compromised​

Kaspersky researchers found that the attackers had not breached each torrent tracker. They instead compromised itorrents[.]org, a public repository used by multiple trackers, causing magnet-link requests to return a different, malicious torrent file.

The malicious torrent delivered an executable disguised with a long movie-related name. One common example was “the odyssey (2026) [1080p] [webrip] [5.1].exe,” with the .exe ending potentially hidden from view by the filename’s length.

What MovieReaper can do​

Once launched, MovieReaper downloads further stages and creates a persistent copy at C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. Persistence means the malware is set up to return after Windows restarts.

Its final file-management module gives a remote operator broad access to stored data. The attacker can browse folders, read, upload, download, rename, move or delete files, and preview selected content before stealing it.

The researchers suspect additional modules may be delivered when requested, but did not confirm what those other modules would do.

Countries and organizations affected​

Kaspersky observed infection attempts across Europe, Asia and Africa, including Russia, Spain, Germany, Finland, Türkiye, Japan, Nepal, Kenya, Tanzania and Ghana. Targets included home users as well as enterprise, government, IT, retail, transportation and agriculture organizations.

What torrent users should check​

  • Run a full antivirus scan, particularly if you recently opened an .exe file presented as a movie. Kaspersky detects the threat as HEUR:Trojan.Win64.Agent.gen.
  • Check for C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. Its presence is a reported indicator of this campaign; do not confuse it with legitimate Microsoft Edge files in their normal installation folders.
  • Review security or network logs for contact with deadhub[.]org or 193.23.118[.]155, the first-stage command server indicators reported by the researchers.
  • If you find an indicator, disconnect the PC from the network, quarantine the detected malware with your security software and change important passwords from a separate, clean device.
 
Yes this has nearly got me before. Snatch movie 1080P torrent with malicious subtitle file. Luckily picked up by MD.
I watch a lot of Linux Distro TV shows on my Apple TV and Firestick. I use Plex as server, and SABNZBD. Usenet only.
How does a malicious subtitle file affect me.