Crypto

Fake Downloads of The Odyssey Are Carrying Crypto-Stealing Malware

Bitdefender found fake pirated copies of the film circulating within days of release, disguised as HD video files but actually carrying Lumma Stealer. The malware takes authentication cookies as well as wallets, which means multi-factor authentication does not protect the accounts it reaches.

⏱ 2 min read Crypto
Quick Summary
  • Bitdefender confirmed fake pirated downloads of 'The Odyssey' appeared within days of the film's release and contain Lumma Stealer malware disguised as WEBRip or Blu-ray video files.
  • Lumma Stealer harvests browser passwords, payment details, remote desktop credentials, cryptocurrency wallets, and authentication cookies, allowing account takeover even with MFA enabled.
  • The campaign mirrors a near-identical 2025 attack using fake 'Mission: Impossible - The Final Reckoning' files, and fits a broader pattern of wallet-draining malware hidden inside desirable content.

Fans looking to pirate Christopher Nolan’s new blockbuster ‘The Odyssey’ risk handing over far more than a ticket price. Cybersecurity firm Bitdefender has confirmed that fake pirated downloads of the newly released film are already circulating online, bundled with Lumma Stealer, an information-stealing malware that targets cryptocurrency wallets, browser passwords, and authentication cookies.

Malware Arrives Within Days of Release

According to Bitdefender, the malicious files appeared within days of the film’s launch. The fake downloads are disguised as high-definition WEBRip and Blu-ray rips, with filenames carefully crafted to mimic legitimate torrent releases. In reality, the files are Windows executables designed to infect machines rather than play any video.

To make the deception more convincing, attackers replace file icons with ones resembling VLC Media Player or standard video formats. The trick is made more effective because Windows hides file extensions by default, leaving many users unable to distinguish an ‘.exe’ file from an actual movie file.

What Lumma Stealer Actually Does

Once executed, Lumma Stealer conducts a broad sweep of the infected machine. It scrapes browser-saved passwords, saved payment details, autofill data, remote desktop credentials and cryptocurrency wallets. It also lifts authentication cookies, which can allow attackers to hijack accounts even when multi-factor authentication is enabled.

Bitdefender said its products blocked the downloads in question and flagged command-and-control domains associated with the operation.

A Familiar Playbook

Bitdefender noted that the campaign closely mirrors a near-identical operation from 2025 that embedded Lumma Stealer inside fake ‘Mission: Impossible – The Final Reckoning’ files, suggesting the same or similarly organised threat actors are behind both schemes.

The pattern is well established across the threat landscape. Over recent years, wallet-draining malware has been smuggled through fake CAPTCHA pages routed via BNB Chain, the SparkKitty campaign that inserted wallet-stealing code into mobile apps, malicious ‘anime girl’ wallpapers targeting Steam gamers, and a booby-trapped Python library seeded into developer toolchains.

The Common Thread

In each case, the malware rides inside something the victim actively wants, whether a pirated film, a game mod, or a coding package. Bitdefender’s advice is direct: stick to legitimate streaming services, never run an executable promoted as a video file, and enable Windows’ file-extension display setting so a disguised ‘.exe’ cannot pass itself off as a movie.

⚖️ Our Verdict ⚖️ Watch and Wait

There is no market direction in a malware campaign, but there is something worth knowing. The detail most people miss is the cookie theft, because a stolen session cookie is already past two-factor authentication, so an account can be taken over without the attacker ever needing a password or a code. Turning on file extensions in Windows costs nothing and removes the trick this campaign depends on.