PDN

MovieReaper: the pirated film that opens the door to hackers

6 min read

Illustration for the article: MovieReaper: the pirated film that opens the door to hackers

The file is called “the odyssey (2026) [1080p] [webrip] [5.1].exe”. To an internet user in a hurry to see Christopher Nolan’s latest film without paying, it looks like any pirated copy. But it is not a film: it is the entry point of a hacking campaign that Kaspersky has named MovieReaper.

Revealed on September 17, 2026 by Kaspersky researchers, this campaign has already hit several hundred victims in at least ten countries, including businesses and public administrations. It is a reminder of something we often repeat on this blog: pirated content is never free.

A poisoned torrent archive

The attackers’ trick comes down to one idea. Rather than publishing their fake files on each torrent site, one by one, they modified a public torrent archive, itorrents, which feeds many trackers. According to Kaspersky, this allowed them to “reach users of multiple trackers without having to compromise each platform individually.” At the time the report was published, the archive was still compromised.

The group behind MovieReaper is not new to this: the researchers place the start of its activity in October 2025, and the discovery of this campaign in mid-August 2026.

Four steps to taking control of the computer

Once the fake film is launched, the infection unfolds in four stages:

  1. The loader downloads a first piece of malicious code from a server controlled by the attackers;
  2. this code fetches the address of the command server from the Solana blockchain, where it is stored in encrypted form;
  3. a module bypasses Windows protections and installs itself permanently, posing as a Microsoft Edge telemetry component;
  4. the final implant gives the attackers 21 commands to read, upload and manipulate the victim’s files.

The use of the blockchain is not a detail. An address recorded in a public blockchain cannot be erased the way a domain name can be suspended: the attackers can change servers at any time without modifying their software.

The recorded victims are in Russia, Türkiye, Japan, Kenya, Uganda, Colombia, Spain, the Netherlands, Belgium and Germany. Canada is not named, but the compromised archive feeds trackers used all over the world.

Not an isolated case

MovieReaper is part of a long series. In late 2025, Bitdefender described a fake torrent of the film One Battle After Another: a Windows shortcut ran code hidden in a subtitle file, then installed Agent Tesla, software that steals passwords and banking data. The fake file had thousands of shares.

Live sports are not spared. During the 2026 World Cup, Malwarebytes spotted more than 40 clone streaming sites where, in Malwarebytes’ words, “Clicking Play doesn’t play anything”: the button leads to fake virus alerts, fake updates that install malware, or subscription traps. According to a Malwarebytes study published in November 2025, 32% of illegal stream users suffered a direct financial loss.

The authorities have drawn the consequences. In Operation Offsides, the U.S. Department of Justice seized more than 1,000 domains that were illegally streaming World Cup matches. In the announcement, an official of Homeland Security Investigations warned that their operators “might also be planning to inject malware or steal your payment information.”

And the problem is structural: the Digital Citizens Alliance already estimated in 2022 that malicious ads accounted for 12% of ads on pirate sites, or about US$121 million a year.

A risk for businesses, not just individuals

Among MovieReaper’s victims are businesses in the IT, consulting, retail, transportation and agriculture sectors. All it takes is for one employee to play a pirated film on a work computer for the implant to gain access to the company’s files.

For a small or medium-sized business, the consequences can be heavy: theft of documents, downstream ransomware, and the incident reporting obligations set out in Quebec’s Law 25 when personal information is affected.

Our advice

For the public:

  • A film that ends in “.exe” or “.lnk”, or that asks you to open a shortcut, is not a film.
  • A “Play” or “Enable sound” button that opens a window, an update or a download: close the tab.
  • Be wary of files with very long names: they are often used to hide the real extension.

For businesses:

  • Ban file-sharing software on workstations and show file extensions in Windows.
  • Train your teams: a pirated film downloaded at the office is an entry point into the whole network.

For rights holders:

  • Fake files that carry the title of your films also harm your brand: they associate your work with a scam. They must be reported and removed like any other pirated copy.
  • Kaspersky points it out: the first stage of MovieReaper relies on a single domain and a single IP address. Taking down that link is enough to block the rest of the infection. Quickly reporting compromised servers and archives therefore has a real effect.

At AgencePDN, our monitoring spots every night the copies of your titles on torrent and download sites, including fake files that use your name as bait. If you want to know what is circulating under the title of your next film, start with our free analysis.

Sources

  • Kaspersky Securelist, MovieReaper (September 17, 2026): securelist.com
  • Bitdefender, fake One Battle After Another torrent: bitdefender.com
  • Malwarebytes, World Cup streaming sites (June 16, 2026): malwarebytes.com
  • Flare, underground economy of illegal World Cup streaming (June 4, 2026): flare.io
  • U.S. Department of Justice, Operation Offsides (July 20, 2026): justice.gov
  • Digital Citizens Alliance, malicious ads on pirate sites (2022): digitalcitizensalliance.org

On the same topic

Is your content pirated? We can get it removed.