MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide

MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide

MovieReaper malware spreads through compromised Odyssey torrents, infecting hundreds of victims while using Solana to locate command-and-control infrastructure.

Listen to this article

0:00

Press play to start listening

In mid-August 2026, Kaspersky researchers discovered a large-scale malware campaign affecting computer systems across multiple countries. Researchers identified a previously unknown modular framework named “MovieReaper,” which spreads through a compromised torrent file repository.

Now, the company has identified several hundred victims, including individual users and organizations. Kaspersky detects the malware as HEUR:Trojan.Win64.Agent.gen.

The campaign affected users and organizations across Europe, Asia and Africa, with infections identified in countries including Russia, Türkiye, Japan, Kenya, Spain and Germany. Affected organizations represented several sectors, including government, enterprise, IT, consulting, retail, transportation and agriculture.

How the Attack Begins

Torrent downloads have been used to spread malware for years. MovieReaper however, took advantage of the same habit, but the attackers went after a source used by multiple torrent trackers. They compromised itorrents.org, a public repository of torrent files, so malicious torrent files could be sent to users through trackers relying on the repository.

When users attempted to download torrents through magnet links, the compromised repository could return a different, malicious torrent file that led to the MovieReaper loader.

One executable seen by Kaspersky was named the odyssey (2026) (1080p) (webrip) (5.1).exe. Running the file launches the first-stage loader, which checks for security tools and sandbox environments before continuing the infection.

MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide
(Source: Secure List)

Inside MovieReaper’s Multi-Stage Attack

The loader downloads shellcode from its first C2 server before the malware turns to the Solana blockchain to obtain the address of another C2 server. This gives the attackers a way to change the next server address without putting it directly into the malware and makes the later infrastructure harder to disrupt through conventional blocking and takedowns.

The malware does more than simply download another payload. A later stage bypasses User Account Control (UAC), establishes persistence and loads additional modules. Its final file manager contains 21 commands that let attackers upload, download, read, create, copy, rename, move and delete files, while also retrieving file and image previews.

Kaspersky also found related activity dating back to October 2025. The researchers said the campaign has changed over time, including modifications to the loader that make it harder to detect. Kaspersky researchers said the framework’s modular design and in-memory execution could also make it easier to reuse in future campaigns.

Infection chain (Source: Secure List)

What Users Should Watch For

The filename used in this campaign is a warning sign on its own. A movie download ending in .exe is an executable, not a video file, so avoid running it. A legitimate movie file would have a video format like .mp4 or .mkv, not .exe. Avoiding unofficial movie downloads in the first place removes the initial step attackers need to start an infection.

MovieReaper is not the first malware campaign to use The Odyssey as a lure. Cybercriminals have repeatedly used popular movie releases to spread malware through fake torrents.

In December 2025, Hackread.com reported that a torrent posing as Leonardo DiCaprio’s One Battle After Another delivered Agent Tesla malware to Windows users.

Earlier that year, another campaign used a fake Snow White movie torrent containing a malicious executable disguised as a codec, which disabled Windows security protections and downloaded additional malware

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts