securelist.com iTorrents.org Compromised to Distribute MovieReaper Malware
Article Content
- •iTorrents.org is compromised, distributing MovieReaper malware via torrents.
- •Hundreds of victims across multiple countries are affected, including organizations.
- •Malware uses the Solana blockchain for communication and has extensive file manipulation capabilities.
iTorrents.org has been compromised to spread a new Windows-based malware called MovieReaper, affecting several hundred victims across multiple countries, including Russia, Japan, and Spain. Kaspersky reported that the malware is distributed through disguised torrents of popular films, leading users to download malicious executable files instead of legitimate content. The malware communicates with the attackers via the Solana blockchain and possesses capabilities to manipulate and exfiltrate files. Victims primarily used torrent trackers that relied on iTorrents.org, which remains compromised. Kaspersky's investigation revealed that the malware loader initiates the infection chain, and the threat actors have not compromised individual torrent platforms but rather the repository itself. As of now, the malicious torrents continue to circulate, posing a significant risk to users downloading from these sources.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Mirage Kitten and MovieReaper in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Mirage Kitten Targets Aviation and FinTech with New Cross-Platform Malware The Iranian cyberespionage group Mirage Kitten has launched a campaign targeting technology professionals in the aviation and FinTech sectors across the Middle East and Africa. This operation involves the use of two newly discovered malware families, NodeRabbit and PollCat, both of which are cross-platform remote…
Fire Ant Threat Actor Targets Trusted Infrastructure in 2026 The China-nexus threat actor known as Fire Ant has evolved its tactics in 2026, transitioning from targeting VMware hypervisors to compromising trusted infrastructure, including Cisco routers, TACACS authentication servers, and Linux management hosts. This shift allows Fire Ant to collect credentials, traffic, and…