A newly discovered malware framework called MovieReaper is spreading through malicious torrent downloads that appear as popular movies This article explores trackers moviereaper exploits. . The framework is modular and gives attackers 21 remote file-management commands, allowing them to steal, inspect, alter, and delete data from infected systems.

Researchers discovered the campaign in mid-August 2026 after identifying victims in various countries, including Russia, Türkiye, Japan, Kenya, Uganda, Colombia, Spain, the Netherlands, Belgium, and Germany. MovieReaper users avoided direct interaction with torrent-tracker websites by targeting itorrents[. ]org, a public repository used by multiple trackers. MovieReaper Exploits File Access (Source: securelist) This tactic poses significant risks to those downloading pirated content, as installation instructions frequently advise users to disable antivirus protection before running cracked software.

Even if defenders block a known C2 IP address, operators might update the address stored in the blockchain account, redirecting infected devices to new infrastructure. MovieReaper then downloads modules directly into memory. One observed module bypasses User Account Control and establishes persistence by copying the malware to: C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe Indicators of Compromise IOC Type Indicator Details Detection name HEUR:Trojan.Win64.Agent.gen Kaspersky detection name for MovieReaper File hash (MD5) 4334BBAEA8DE33BF9D45E9B4E4E3BC2 Associated malicious sample