Hackers Compromise iTorrents Repository to Spread MovieReaper Malware Through Fake Movie Torrents

Abeerah Hashim  - Security Expert
Last updated: September 18, 2026
Share
Hackers Hijack Torrent Hub to Spread MovieReaper Malware Through Fake Films
  • Hackers broke into iTorrents.org, a shared torrent file hub, and used it to sneak malware onto victims' computers.
  • The malware, called MovieReaper, hides inside fake movie files like Christopher Nolan's The Odyssey.
  • Once it runs, the malware can give attackers full control over files on the infected computer.

Cybercriminals have found a clever new trick to spread malware. They broke into a shared torrent repository that many trackers rely on. Then they used it to push fake movie downloads onto unsuspecting users.

According to SecureList, the campaign started around mid-August 2026. It has already reached several hundred victims across many countries. Affected people live in Spain, the Netherlands, Belgium, Germany, Russia, Türkiye, Japan, Kenya, Uganda and Colombia. Organizations in government, tech, consulting, retail, transportation and farming have also been hit.

Attackers hijacked a shared Torrent Hub

Kaspersky’s investigation found something interesting. The attackers did not need to break into every torrent tracker one by one. Instead, they compromised a single source, itorrents.org, which many torrent trackers use to fetch torrent files.

Kaspersky has faced scrutiny beyond individual malware campaigns, particularly over concerns surrounding its security and operations. U.S. authorities also moved to step up a security probe into the company following the Russia-Ukraine war, adding another layer to the scrutiny surrounding the cybersecurity firm.

This single breach let the attackers reach users on several different torrent sites at once. When people clicked certain magnet links, the hijacked hub could quietly swap in a fake torrent file instead of the real one.

That fake file then led users to a Windows program disguised as a movie. Kaspersky studied one example closely. The file mimicked a copy of The Odyssey, named something like odyssey (2026) [1080p] [webrip] [5.1].exe. Researchers explained that the long file name and a familiar-looking icon made the fake program easy to mistake for a real movie file.

Kaspersky gave this malware family a name: MovieReaper. Per the company’s findings, the attack runs in several stages. It also uses tricks meant to dodge security scans and stay hidden on infected machines.

Security.NL, a Dutch outlet, also reported on the campaign, confirming that European users and organizations were among the hardest hit. This is not the first time criminals have used the film’s name as bait. Malwarebytes flagged similar piracy scams tied to The Odyssey just hours after its release back in July.

Malware grants remote access to victim files

Once a victim opens the fake movie file, the infection unfolds in stages. Kaspersky found that the malware plants itself deep inside the system. Eventually, it hands attackers wide control over files stored on the computer.

The final stage can read, upload, download, copy, move, rename and delete files. In short, whoever controls the malware can quietly reach into a victim’s folders and move things around at will.

There is another twist worth noting. One stage of MovieReaper uses the Solana blockchain to find its command server. Instead of pointing to one fixed address, the malware pulls that address from blockchain data. This trick makes the malware’s network harder to shut down than a normal setup would be.

Kaspersky’s official statement noted that the compromised repository was still active when the report came out on September 17. That means new victims could still be at risk right now. This part of the story has not been fully resolved yet, so the threat remains live.

Stay cautious with downloads

This incident shows a real danger in trusting shared, third-party sources. One weak link at the top can quietly poison files handed out through many different services below it. Avoid downloading movies, shows, or software from torrent sites and other unofficial sources. Even a file that looks familiar can carry hidden threats. Names and icons can be faked easily.

Check file extensions carefully before opening anything. A movie should never end in .exe. That ending means it is a program, not a video file, and programs can install malware silently. Keep your antivirus software active and updated at all times. Good security software can catch many threats before they cause damage. Update it regularly so it recognizes new dangers like MovieReaper.

Watch your computer for odd behavior after downloading new files. Slower performance, strange pop-ups, or missing files can signal an infection. Act quickly and scan your system if anything feels off.

Stick to trusted, official platforms for movies and shows whenever you can. Paid streaming services and verified stores carry far less risk. The small cost is worth avoiding a serious security headache.

Report suspicious files or links if your antivirus tool allows it. Sharing this information helps researchers track and stop threats faster. Small actions like this protect the wider online community too.

Stay alert and think twice before clicking unfamiliar download links. A moment of caution can save your files, your data, and your peace of mind. As this case shows, even one trusted-looking source can turn into a trap.

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.