Skip to content
iTorrents.org Compromised To Spread Windows Malware, Kaspersky Says

iTorrents.org Compromised To Spread Windows Malware, Kaspersky Says

Uk.Pcmag September 17, 2026

A hacker appears to have hijacked iTorrents.org, a public repository for torrents , to spread a new Windows-based malware, according to the antivirus provider Kaspersky. Kaspersky flagged the issue on Thursday after discovering the malware infecting “several hundred victims, including both individual users and organizations” in countries such as Russia, Japan, Spain, the Netherlands and Colombia. Kaspersky’s investigation discovered the malware was circulating through disguised popular and pirated movies, including Christopher Nolan’s The Odyssey , which has only been released in theaters. The company’s report added, “our initial analysis revealed a common factor among the victims: all had used torrent trackers,” which can be used to download pirated films and TV shows. Kaspersky’s researchers then spotted user reports connected to the issue. This included one on torrents on the site 1337x —which is frequently used for online piracy— delivering an executable file, rather than a media file. However, Kaspersky took a closer look and says the malicious torrents have actually been coming from iTorrents.org, a free service that caches torrent files and can be used as a backup for piracy providers. “As a result, torrent trackers that relied on this repository began inadvertently distributing malicious torrent files to their users. This approach is particularly powerful because the threat actors can reach users of multiple trackers without compromising each platform individually,” the antivirus provider’s report says. Kaspersky even warns that iTorrent.org “remains compromised.” “When a user attempts to download a torrent using a magnet link, the legitimate torrent archive instead returns a different torrent file. This malicious torrent leads to the download of the malware loader. It is used to deploy a framework that we dubbed MovieReaper.” After Kaspersky published its report, we visited iTorrents.org in an attempt to replicate the issue. At first, the site redirected us itorrents.net, which appeared to be safe. But when we visited iTorrents.org again, it immediately triggered our browser to download "AAC402C085D3DCB8B9348FDEC001CD8ECBFDCC862.exe.torrent" for a mysterious .exe file 865MB in size. Microsoft's Windows Defender later flagged the executable file as a severe malware threat, specifically " Trojan;Win32/Sonbokli.A!cl " iTorrents.org doesn’t have any information, so it’s unclear if the service is trying to rectify the issue. Attempts to visit itorrents.net have also started to trigger the same malicious download. In the meantime, Kaspersky says the malicious torrents will download a .exe file with a long file name, likely to hide the executable nature of the payload. The resulting MovieReaper malware communicates back to the hackers by tapping the Solana blockchain, and contains 21 different functions, including the ability “to download, upload, read files on the system,” and manipulate and exfiltrate files. Kaspersky’s investigation also found the malware infected organizations spanning “a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.”

Kaspersky flagged the issue on Thursday after discovering the malware infecting “several hundred victims, including both individual users and organizations” in countries such as Russia, Japan, Spain, the Netherlands and Colombia. Kaspersky’s investigation discovered the malware was circulating through disguised popular and pirated movies, including Christopher Nolan’s The Odyssey , which has only been released in theaters. The company’s report added, “our initial analysis revealed a common factor among the victims: all had used torrent trackers,” which can be used to download pirated films and TV shows. Kaspersky’s researchers then spotted user reports connected to the issue. This included one on torrents on the site 1337x —which is frequently used for online piracy— delivering an executable file, rather than a media file. However, Kaspersky took a closer look and says the malicious torrents have actually been coming from iTorrents.org, a free service that caches torrent files and can be used as a backup for piracy providers. “As a result, torrent trackers that relied on this repository began inadvertently distributing malicious torrent files to their users. This approach is particularly powerful because the threat actors can reach users of multiple trackers without compromising each platform individually,” the antivirus provider’s report says. Kaspersky even warns that iTorrent.org “remains compromised.” “When a user attempts to download a torrent using a magnet link, the legitimate torrent archive instead returns a different torrent file. This malicious torrent leads to the download of the malware loader. It is used to deploy a framework that we dubbed MovieReaper.” After Kaspersky published its report, we visited iTorrents.org in an attempt to replicate the issue. At first, the site redirected us itorrents.net, which appeared to be safe. But when we visited iTorrents.org again, it immediately triggered our browser to download "AAC402C085D3DCB8B9348FDEC001CD8ECBFDCC862.exe.torrent" for a mysterious .exe file 865MB in size. Microsoft's Windows Defender later flagged the executable file as a severe malware threat, specifically " Trojan;Win32/Sonbokli.A!cl " iTorrents.org doesn’t have any information, so it’s unclear if the service is trying to rectify the issue. Attempts to visit itorrents.net have also started to trigger the same malicious download. In the meantime, Kaspersky says the malicious torrents will download a .exe file with a long file name, likely to hide the executable nature of the payload. The resulting MovieReaper malware communicates back to the hackers by tapping the Solana blockchain, and contains 21 different functions, including the ability “to download, upload, read files on the system,” and manipulate and exfiltrate files. Kaspersky’s investigation also found the malware infected organizations spanning “a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.”

Kaspersky’s investigation discovered the malware was circulating through disguised popular and pirated movies, including Christopher Nolan’s The Odyssey , which has only been released in theaters. The company’s report added, “our initial analysis revealed a common factor among the victims: all had used torrent trackers,” which can be used to download pirated films and TV shows. Kaspersky’s researchers then spotted user reports connected to the issue. This included one on torrents on the site 1337x —which is frequently used for online piracy— delivering an executable file, rather than a media file. However, Kaspersky took a closer look and says the malicious torrents have actually been coming from iTorrents.org, a free service that caches torrent files and can be used as a backup for piracy providers. “As a result, torrent trackers that relied on this repository began inadvertently distributing malicious torrent files to their users. This approach is particularly powerful because the threat actors can reach users of multiple trackers without compromising each platform individually,” the antivirus provider’s report says. Kaspersky even warns that iTorrent.org “remains compromised.” “When a user attempts to download a torrent using a magnet link, the legitimate torrent archive instead returns a different torrent file. This malicious torrent leads to the download of the malware loader. It is used to deploy a framework that we dubbed MovieReaper.” After Kaspersky published its report, we visited iTorrents.org in an attempt to replicate the issue. At first, the site redirected us itorrents.net, which appeared to be safe. But when we visited iTorrents.org again, it immediately triggered our browser to download "AAC402C085D3DCB8B9348FDEC001CD8ECBFDCC862.exe.torrent" for a mysterious .exe file 865MB in size. Microsoft's Windows Defender later flagged the executable file as a severe malware threat, specifically " Trojan;Win32/Sonbokli.A!cl " iTorrents.org doesn’t have any information, so it’s unclear if the service is trying to rectify the issue. Attempts to visit itorrents.net have also started to trigger the same malicious download. In the meantime, Kaspersky says the malicious torrents will download a .exe file with a long file name, likely to hide the executable nature of the payload. The resulting MovieReaper malware communicates back to the hackers by tapping the Solana blockchain, and contains 21 different functions, including the ability “to download, upload, read files on the system,” and manipulate and exfiltrate files. Kaspersky’s investigation also found the malware infected organizations spanning “a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.”

Kaspersky’s researchers then spotted user reports connected to the issue. This included one on torrents on the site 1337x —which is frequently used for online piracy— delivering an executable file, rather than a media file. However, Kaspersky took a closer look and says the malicious torrents have actually been coming from iTorrents.org, a free service that caches torrent files and can be used as a backup for piracy providers. “As a result, torrent trackers that relied on this repository began inadvertently distributing malicious torrent files to their users. This approach is particularly powerful because the threat actors can reach users of multiple trackers without compromising each platform individually,” the antivirus provider’s report says. Kaspersky even warns that iTorrent.org “remains compromised.” “When a user attempts to download a torrent using a magnet link, the legitimate torrent archive instead returns a different torrent file. This malicious torrent leads to the download of the malware loader. It is used to deploy a framework that we dubbed MovieReaper.” After Kaspersky published its report, we visited iTorrents.org in an attempt to replicate the issue. At first, the site redirected us itorrents.net, which appeared to be safe. But when we visited iTorrents.org again, it immediately triggered our browser to download "AAC402C085D3DCB8B9348FDEC001CD8ECBFDCC862.exe.torrent" for a mysterious .exe file 865MB in size. Microsoft's Windows Defender later flagged the executable file as a severe malware threat, specifically " Trojan;Win32/Sonbokli.A!cl " iTorrents.org doesn’t have any information, so it’s unclear if the service is trying to rectify the issue. Attempts to visit itorrents.net have also started to trigger the same malicious download. In the meantime, Kaspersky says the malicious torrents will download a .exe file with a long file name, likely to hide the executable nature of the payload. The resulting MovieReaper malware communicates back to the hackers by tapping the Solana blockchain, and contains 21 different functions, including the ability “to download, upload, read files on the system,” and manipulate and exfiltrate files. Kaspersky’s investigation also found the malware infected organizations spanning “a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.”

However, Kaspersky took a closer look and says the malicious torrents have actually been coming from iTorrents.org, a free service that caches torrent files and can be used as a backup for piracy providers. “As a result, torrent trackers that relied on this repository began inadvertently distributing malicious torrent files to their users. This approach is particularly powerful because the threat actors can reach users of multiple trackers without compromising each platform individually,” the antivirus provider’s report says. Kaspersky even warns that iTorrent.org “remains compromised.” “When a user attempts to download a torrent using a magnet link, the legitimate torrent archive instead returns a different torrent file. This malicious torrent leads to the download of the malware loader. It is used to deploy a framework that we dubbed MovieReaper.” After Kaspersky published its report, we visited iTorrents.org in an attempt to replicate the issue. At first, the site redirected us itorrents.net, which appeared to be safe. But when we visited iTorrents.org again, it immediately triggered our browser to download "AAC402C085D3DCB8B9348FDEC001CD8ECBFDCC862.exe.torrent" for a mysterious .exe file 865MB in size. Microsoft's Windows Defender later flagged the executable file as a severe malware threat, specifically " Trojan;Win32/Sonbokli.A!cl " iTorrents.org doesn’t have any information, so it’s unclear if the service is trying to rectify the issue. Attempts to visit itorrents.net have also started to trigger the same malicious download. In the meantime, Kaspersky says the malicious torrents will download a .exe file with a long file name, likely to hide the executable nature of the payload. The resulting MovieReaper malware communicates back to the hackers by tapping the Solana blockchain, and contains 21 different functions, including the ability “to download, upload, read files on the system,” and manipulate and exfiltrate files. Kaspersky’s investigation also found the malware infected organizations spanning “a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.”

Kaspersky even warns that iTorrent.org “remains compromised.” “When a user attempts to download a torrent using a magnet link, the legitimate torrent archive instead returns a different torrent file. This malicious torrent leads to the download of the malware loader. It is used to deploy a framework that we dubbed MovieReaper.” After Kaspersky published its report, we visited iTorrents.org in an attempt to replicate the issue. At first, the site redirected us itorrents.net, which appeared to be safe. But when we visited iTorrents.org again, it immediately triggered our browser to download "AAC402C085D3DCB8B9348FDEC001CD8ECBFDCC862.exe.torrent" for a mysterious .exe file 865MB in size. Microsoft's Windows Defender later flagged the executable file as a severe malware threat, specifically " Trojan;Win32/Sonbokli.A!cl " iTorrents.org doesn’t have any information, so it’s unclear if the service is trying to rectify the issue. Attempts to visit itorrents.net have also started to trigger the same malicious download. In the meantime, Kaspersky says the malicious torrents will download a .exe file with a long file name, likely to hide the executable nature of the payload. The resulting MovieReaper malware communicates back to the hackers by tapping the Solana blockchain, and contains 21 different functions, including the ability “to download, upload, read files on the system,” and manipulate and exfiltrate files. Kaspersky’s investigation also found the malware infected organizations spanning “a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.”

After Kaspersky published its report, we visited iTorrents.org in an attempt to replicate the issue. At first, the site redirected us itorrents.net, which appeared to be safe. But when we visited iTorrents.org again, it immediately triggered our browser to download "AAC402C085D3DCB8B9348FDEC001CD8ECBFDCC862.exe.torrent" for a mysterious .exe file 865MB in size. Microsoft's Windows Defender later flagged the executable file as a severe malware threat, specifically " Trojan;Win32/Sonbokli.A!cl " iTorrents.org doesn’t have any information, so it’s unclear if the service is trying to rectify the issue. Attempts to visit itorrents.net have also started to trigger the same malicious download. In the meantime, Kaspersky says the malicious torrents will download a .exe file with a long file name, likely to hide the executable nature of the payload. The resulting MovieReaper malware communicates back to the hackers by tapping the Solana blockchain, and contains 21 different functions, including the ability “to download, upload, read files on the system,” and manipulate and exfiltrate files. Kaspersky’s investigation also found the malware infected organizations spanning “a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.”

iTorrents.org doesn’t have any information, so it’s unclear if the service is trying to rectify the issue. Attempts to visit itorrents.net have also started to trigger the same malicious download. In the meantime, Kaspersky says the malicious torrents will download a .exe file with a long file name, likely to hide the executable nature of the payload. The resulting MovieReaper malware communicates back to the hackers by tapping the Solana blockchain, and contains 21 different functions, including the ability “to download, upload, read files on the system,” and manipulate and exfiltrate files. Kaspersky’s investigation also found the malware infected organizations spanning “a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.”

In the meantime, Kaspersky says the malicious torrents will download a .exe file with a long file name, likely to hide the executable nature of the payload. The resulting MovieReaper malware communicates back to the hackers by tapping the Solana blockchain, and contains 21 different functions, including the ability “to download, upload, read files on the system,” and manipulate and exfiltrate files. Kaspersky’s investigation also found the malware infected organizations spanning “a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.”

Kaspersky’s investigation also found the malware infected organizations spanning “a wide range of sectors, including enterprise, government, IT, consulting, retail, transportation, and agriculture.”