Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware itself is not heavily obfuscated, apart from the fact that strings are encrypted with a custom stream cipher.
The malware avoids making LoadLibrary and GetProcAddress calls ... Instead, it searches for loaded libraries ... and then performs manual parsing of loaded DLL to calculate the address of function.
Исполняемый файл маскируется с помощью длинного имени файла и иконки известного приложения, например VLC; длинные имена предположительно скрывают расширение «.exe» в конце.
Стадия 3 ... маскирует исходный бинарный файл под C:\ProgramData\Microsoft\Windows\Telemetry\msedge.exe и перезапускает себя.
Most of the filenames are rather large, presumably, to hide the '.exe' extension at the end.
The second stage of this malware performs an HTTPS request to the Solana blockchain at the /getAccountInfo endpoint... The second stage payload communicates with its C2 server strictly through HTTPS.
[The campaign] leverages the legitimate Solana blockchain via the api.mainnet.solana.com RPC endpoint to deliver the address of the second-stage C2 server.
Вторая стадия выполняет HTTPS-запрос к блокчейну Solana по эндпоинту /getAccountInfo... поле data содержит base64-кодированный адрес второго C2, зашифрованный статическим XOR-ключом.
[The loader] perform[s] network connection to a C2 web-server to download the shellcode... [and] uses them as a path in the HTTP request to download parts of a shellcode.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
MovieReaper is a modular, multi-stage crimeware framework delivered by trojanized torrent downloads. Its loader evades sandbox analysis, downloads and executes shellcode in memory, retrieves second-stage C2 information from a Solana blockchain account, establishes persistence through a UAC bypass, and ultimately deploys a file-management implant that enables remote filesystem enumeration, upload, download, reading, modification, deletion, and preview/thumbnail exfiltration.
Многоэтапный модульный crimeware-фреймворк, распространяемый через вредоносные торрент-загрузчики, маскируемые под фильмы. Его начальный загрузчик уклоняется от песочниц, получает shellcode с C2 по HTTP и запускает его в памяти. Вторая стадия использует Solana для получения адреса следующего C2, применяет HTTPS с закреплением TLS-сертификата и загружает COFF-модули. Последующие модули обходят UAC, обеспечивают закрепление и предоставляют файловый менеджер для удаленного просмотра, чтения, загрузки, выгрузки, изменения и эксфильтрации файлов.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.