MovieReaper Malware Hijacks Odyssey Torrent Files, Leveraging Solana Blockchain for C2
Security researchers have confirmed that the MovieReaper malware is being distributed through compromised files on the popular Odyssey torrent platform, leading to infections across multiple continents. The campaign, first highlighted by cybersecurity outlet Hackread, appears to have affected hundreds of users who downloaded ostensibly legitimate movie torrents.
Odyssey, known for its extensive library of peer‑to‑peer media content, has become a vector for the malicious payload after threat actors injected the malware into popular torrent releases. Once a victim runs the infected executable, MovieReaper installs a suite of unwanted components, including a backdoor that grants remote access to the attacker.
What distinguishes this operation from previous torrent‑based malware campaigns is its reliance on the Solana blockchain to locate command‑and‑control (C2) servers. By embedding blockchain addresses within the malware, the authors can dynamically retrieve the location of their infrastructure without hard‑coding IP addresses, making detection and takedown more difficult.
Analysts note that the use of a public blockchain for C2 resolution reflects a broader trend among cybercriminals to exploit decentralized technologies. Solana’s high throughput and low transaction costs provide an attractive medium for transmitting small data packets that can point infected hosts to malicious endpoints.
The impact of the MovieReaper distribution is still being quantified, but early reports indicate that the infections have spread beyond typical torrent‑sharing regions, reaching users in Europe, North America, and parts of Asia. Victims have reported system slowdowns, unauthorized cryptocurrency mining, and the appearance of additional adware.
Authorities and security firms are urging torrent users to verify the integrity of downloaded files, employ reputable antivirus solutions, and consider alternative, legal sources for media consumption. Meanwhile, investigators are working with the operators of Odyssey to identify the compromised uploads and remove the malicious content, while also monitoring blockchain activity for further signs of the threat actor’s infrastructure.
Comments (0)
Be the first to comment.
Join the discussion