MovieReaper Malware: From Movie Download to Malware Infection
AI-summarised brief · reviewed before publication
MovieReaper, first seen in September 2026, is a modular malware that blends a remote‑access trojan with a loader, targeting x86‑64 Windows systems. It spreads via compromised torrent‑file infrastructure, delivering a disguised loader that passes anti‑sandbox checks, downloads shellcode, and retrieves command‑and‑control endpoints from a Solana blockchain. Subsequent stages establish HTTPS communication with certificate pinning, load additional COFF modules, perform UAC bypass, and persist by masquerading as C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe. The final implant offers full file‑management, exfiltration, and remote control, enabling durable, stealthy post‑compromise activity across individuals and organizations worldwide.
💡 Why It Matters
- · The use of blockchain‑based C2 and torrent‑file delivery expands the attack surface beyond traditional phishing, enabling attackers to reach a global user base with minimal effort.
- · This strategy demonstrates how malware can exploit legitimate infrastructure to evade detection and maintain persistent, high‑impact access.