[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f-KzChJ0V1OFyhriAL4V-_SvbKnlSsHVOhVHIgT9CeVI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"a37aa62c-33b8-47cd-a265-91e29009fdac","moviereaper-trojan-spreads-via-compromised-torrents-using-blockchain-c2","18cc4a76-bb9a-4821-ae9c-ecb2e156884c","MovieReaper Trojan Spreads via Compromised Torrents Using Blockchain C2","The MovieReaper campaign exploits users who download pirated content from torrent platforms, embedding a multi-stage Trojan inside files disguised as popular movies. By leveraging the Solana blockchain as its command and control infrastructure, the attackers made detection and takedown significantly harder for security teams. This highlights how threat actors exploit both user trust in informal distribution channels and novel technologies to evade traditional defenses. The campaign's global reach across both individuals and organizations underscores that risky personal downloading behaviors can have serious enterprise-level consequences.","**Immediate actions:**\n- Block access to known torrent and peer-to-peer file-sharing platforms on all corporate and managed devices.\n- Deploy endpoint detection and response (EDR) tools capable of identifying multi-stage malware execution chains, including blockchain-based C2 communication.\n- Scan all recently downloaded files from unverified sources using up-to-date antivirus and sandboxing solutions.\n\n**Long-term improvements:**\n- Establish and enforce an Acceptable Use Policy (AUP) that explicitly prohibits downloading pirated or unverified software and media on corporate devices.\n- Integrate threat intelligence feeds that monitor for emerging malware campaigns exploiting unconventional C2 channels such as blockchain networks.\n- Implement application whitelisting to prevent unauthorized or unverified executables from running on endpoints.\n\n**Detection measures:**\n- Monitor outbound network traffic for unusual connections to blockchain nodes or decentralized infrastructure that may indicate C2 activity.\n- Enable behavioral analysis logging on endpoints to detect multi-stage payload execution and lateral movement attempts.\n- Conduct regular user security awareness training focused on the risks of pirated content and social engineering disguised as entertainment media.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 9 – Email and Web Browser Protections","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-53 SI-3 – Malicious Code Protection","NIST SP 800-53 SC-7 – Boundary Protection","NIST SP 800-53 AT-2 – Security Awareness Training","NIST CSF DE.CM-1 – Network Communications Monitoring","MITRE ATT&CK T1102 – Web Service C2 (Blockchain variant)","MITRE ATT&CK T1204 – User Execution: Malicious File","GDPR Article 32 – Security of Processing (for affected EU organizations)","published","2026-09-17T14:20:53.357869+00:00","2026-09-17T14:20:53.271+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fsecurelist.com\u002Fmoviereaper-malware-torrent-odyssey-solana\u002F121344\u002F","the-odyssey-and-trojans-again-moviereaper-attacks-users-in-multiple-countries-vi-9e0dd1","The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":37,"name":38,"slug":39,"description":40,"color":41},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]