Pirated copies of 'The Odyssey' contain Lumma Stealer malware targeting crypto wallets and browser credentials.
Security & Exploits ·
Security firm Bitdefender discovered malicious downloads masquerading as pirated copies of "The Odyssey" within days of the film's release. The fake files, distributed as high-definition movie rips, are actually Windows executables containing Lumma Stealer, malware designed to harvest cryptocurrency wallets, browser passwords, and saved payment credentials from infected machines. Attackers disguise the executable files using video player icons—typically mimicking VLC Media Player—exploiting Windows' default behavior of hiding file extensions to trick users into running them.
Once executed, Lumma Stealer extracts browser passwords, autofill data, remote desktop credentials, and authentication cookies, with the stolen session cookies enabling account takeover even when multi-factor authentication is enabled. Bitdefender blocked the downloads and identified associated command-and-control infrastructure. The campaign mirrors a nearly identical operation from 2025 that distributed the same malware through fake "Mission: Impossible – The Final Reckoning" files.
The "Odyssey" incident exemplifies a broader pattern in which attackers embed wallet-draining malware inside content users actively seek—from pirated films to game modifications to poisoned developer libraries. Security experts advise users to rely on legitimate streaming services, avoid executing files advertised as videos, and enable Windows file-extension display to prevent disguised executables from appearing as legitimate media files.