Kaspersky finds MovieReaper trojan in pirated films, C2 hidden on Solana blockchain
Kaspersky has detailed MovieReaper, a Windows trojan spread via pirated film downloads that has infected several hundred users and organisations across Europe, Asia and Africa. Its second stage retrieves a command server address from the Solana blockchain, making it resistant to domain and IP takedowns.
- Attackers compromised itorrents.org repository rather than individual trackers
- Second stage reads the C2 address from an account on the Solana blockchain
- Malware bypasses UAC and masquerades as msedge.exe in a Telemetry folder
- Final module is a file manager with 21 commands for data theft
Read next
Security