The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents

    Date: 09/21/2026

    Severity: Medium

    Summary

    Torrent trackers are frequently abused to distribute malware disguised as popular movies, games, and pirated software. Attackers use cracked software and malicious installers to infect large numbers of users. During the analysis, researchers discovered a new modular, multi-stage malware framework called MovieReaper. The campaign began by compromising torrent tracker storage to distribute malicious files to users. Hundreds of victims were identified across countries including Russia, Türkiye, Japan, Kenya, Uganda, Colombia, Spain, and the Netherlands.

    Indicators of Compromise (IOC) List 

    Domain/URLs

    deadhub.org

    IP Address

    193.23.118.155

    208.64.33.90

    208.94.246.53

    Hash

    4334BBAEA8DE33BF9D45E9B4E4E3BC2

    4843F9FAFCAE492F11E2D4D33DBB4CDD

    5310CABAE3FBE6DB8742849B588093F9

    A0B13781EDD7CFDAB13D79AFFF3C83C1

    70060341CAF3338697A7DDFE0FB62875

    AD4643EEA15AC286FA47D1131F9EF756

    D0B967571AC8A3863C7F324BF5BDE99C

    D88D550D0FB8E60CFFFF3EA61FF7A067

    Filepath 

    %ProgramData%\Microsoft\Windows\Telemetry\msedge.exe

    Mutex

    Global\E4AyDKzvEhe2hgAr

    Global\fnulSktzSqvVLXHU

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "deadhub.org" or url like "deadhub.org" or siteurl like "deadhub.org"

    Detection Query 2 :

    dstipaddress IN ("193.23.118.155","208.94.246.53","208.64.33.90") or srcipaddress IN ("193.23.118.155","208.94.246.53","208.64.33.90")

    Detection Query 3 :

    md5hash IN ("4843F9FAFCAE492F11E2D4D33DBB4CDD","D0B967571AC8A3863C7F324BF5BDE99C","4334BBAEA8DE33BF9D45E9B4E4E3BC2","5310CABAE3FBE6DB8742849B588093F9","A0B13781EDD7CFDAB13D79AFFF3C83C1","70060341CAF3338697A7DDFE0FB62875","AD4643EEA15AC286FA47D1131F9EF756","D88D550D0FB8E60CFFFF3EA61FF7A067")

    Detection Query 4 :

    datasourcename = "Windows Security" and eventtype = "4663" and objectname like "%ProgramData%\Microsoft\Windows\Telemetry\msedge.exe"

    Detection Query 5 :

    technologygroup = "EDR" and objectname like "%ProgramData%\Microsoft\Windows\Telemetry\msedge.exe"

    Reference: 

    https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/         


    Tags

    MalwareFake softwareRussiaTurkeyJapanColombiaSpain

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags