A previously unknown Windows trojan distributed through pirated film downloads has infected several hundred individuals and organisations across Europe, Asia and Africa, and uses the Solana blockchain to keep its command infrastructure out of reach of conventional takedowns.
Kaspersky’s Global Research and Analysis Team, which named the malware MovieReaper, published its analysis on Securelist late last week. Victims include organisations in the enterprise, government, IT, consulting, retail, transport and agriculture sectors. Kenya, Tanzania and Ghana are among the African countries where infections were found. South Africa is not on the list.
The distribution method is interesting. Rather than compromising torrent sites one by one, the attackers compromised itorrents.org, a public repository of torrent files that multiple trackers draw on. A user clicking a magnet link on a legitimate tracker could be served a different torrent file altogether, one that led to a malware loader. Kaspersky said the repository was still compromised at the time it published.
One sample was named “the odyssey (2026) [1080p] [webrip] [5.1].exe”, the long filename apparently intended to push the .exe extension out of view. The file still had to be opened manually.
The loader first checks whether it is running inside an antivirus sandbox, then retrieves shellcode from a single domain, deadhub.org, falling back to a hardcoded IP address over unencrypted HTTP if that fails.
The second stage then queries the Solana blockchain to find out where to report next. It reads an account on the network that the attackers control, which holds an encrypted address for a second command server. Because that address sits on a public blockchain rather than in the domain name system, it cannot be removed by seizing a domain or adding an IP address to a blocklist.
Full remote access
From there the malware bypasses Windows User Account Control to gain administrator rights without the usual prompt, installs itself as msedge.exe inside a Telemetry folder under ProgramData, and loads a final module that Kaspersky describes as a file manager with 21 commands. Those let an operator list directories, read, copy, move, rename and delete files, and pull thumbnails and previews of documents and images before deciding what is worth taking.
That amounts to full remote access to whatever the infected machine can reach. For anyone who downloaded a film on a work laptop, or on a personal device attached to a corporate network, that may be considerably more than the machine itself.
Kaspersky said the first stage offers the clearest opportunity to disrupt the campaign, because it depends on one domain and one IP address. The later stages are harder to reach. The practical step the research points to for network defenders is monitoring or blocking access to public blockchain endpoints from corporate networks where no legitimate application needs them.
The company detects the malware as HEUR:Trojan.Win64.Agent.gen and has published file hashes, file paths and command server addresses that security teams can use to check their own environments. It traced the same actor’s activity back to October 2025. — (c) 2026 NewsCentral Media
