{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/torrent/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Windows"],"_cs_severities":["high"],"_cs_tags":["trojan","modular","blockchain","torrent","windows","malware"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMovieReaper is a sophisticated multi-stage modular Trojan framework identified in August 2026. The campaign primarily spreads by abusing the itorrents.org repository, which serves malicious torrent files disguised as popular media, such as the film \u0026quot;The Odyssey.\u0026quot; The malware is designed to evade sandbox analysis through manual PEB-based library resolution and syscall-driven shellcode execution. Notably, the framework uses the Solana blockchain to dynamically resolve secondary C2 infrastructure, enhancing resilience against takedown efforts. Once deployed, the malware performs UAC bypasses and establishes persistence by masquerading as Microsoft telemetry components in the C:\\ProgramData\\Microsoft\\Windows\\Telemetry\\ directory. The modular architecture allows the threat actors to deploy additional capabilities via COFF file injection.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUser downloads a malicious torrent file originating from the compromised itorrents.org repository.\u003c/li\u003e\n\u003cli\u003eExecution of the dropper (e.g., \u0026quot;the odyssey (2026).exe\u0026quot;) which uses an anti-debugging mutex (e.g., Global\\fnulSktzSqvVLXHU) and manual PEB parsing to locate system functions.\u003c/li\u003e\n\u003cli\u003eDropper initiates an HTTPS connection to deadhub.org or the fallback 193.23.118.155 to download encrypted shellcode.\u003c/li\u003e\n\u003cli\u003eExecution of the shellcode via NtProtectVirtualMemory and EtwpCreateEtwThread to map and trigger the second-stage payload.\u003c/li\u003e\n\u003cli\u003eThe second-stage implant queries the Solana blockchain account 6pnDGAiHgyPdmckM5Qt1YbanGzrX43WLEU159nRaNLDm to retrieve the address of the secondary C2 server.\u003c/li\u003e\n\u003cli\u003eThe secondary C2 provides a COFF module that performs a UAC bypass and persistence setup.\u003c/li\u003e\n\u003cli\u003eThe process copies itself to C:\\ProgramData\\Microsoft\\Windows\\Telemetry\\msedge.exe and restarts to facilitate further module downloads.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe campaign has infected hundreds of victims, including both individuals and organizations, across diverse regions such as Russia, Türkiye, Japan, Kenya, Uganda, Colombia, and several European nations. Successful execution allows for remote command execution, potential data exfiltration, and long-term persistent access to the victim's environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor for execution of binaries masquerading as Microsoft telemetry components under C:\\ProgramData\\Microsoft\\Windows\\Telemetry.\u003c/li\u003e\n\u003cli\u003eBlock and investigate DNS queries for deadhub.org and network connections to 193.23.118.155.\u003c/li\u003e\n\u003cli\u003eImplement detection for unusual mutex patterns generated by process loaders, such as random strings containing high-entropy characters.\u003c/li\u003e\n\u003cli\u003eDeploy Sigma rules to detect unauthorized execution of binaries from non-standard ProgramData subdirectories.\u003c/li\u003e\n\u003cli\u003eTrain users to avoid downloading pirated media and to be skeptical of installation guides that request disabling antivirus software.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T13:13:14Z","date_published":"2026-09-17T13:13:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-moviereaper-trojan/","summary":"MovieReaper is a multi-stage modular Trojan distributed via compromised torrent files on itorrents.org that leverages the Solana blockchain for C2 discovery and achieves persistence via UAC bypass.","title":"MovieReaper Multi-Stage Trojan Campaign","url":"https://feed.craftedsignal.io/briefs/2026-09-moviereaper-trojan/"}],"language":"en","title":"CraftedSignal Threat Feed - Torrent","version":"https://jsonfeed.org/version/1.1"}