cyberint.com
MovieReaper Malware: From Movie Download to Malware Infection
MovieReaper, first seen in September 2026, is a modular malware that blends a remote‑access trojan with a loader, targeting x86‑64 Windows systems. It spreads via compromised torrent‑file infrastructure, delivering a disguised loader that passes anti‑sandbox checks, downloads shellcode, and retrieves command‑and‑control endpoints from a Solana blockchain. Subsequent stages establish HTTPS communication with certificate pinning, load additional COFF modules, perform UAC bypass, and persist by masquerading as C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. The final implant offers full file‑management, exfiltration, and remote control, enabling [...]