Fake The Odyssey movie downloads used to spread malware that targets passwords and crypto wallets

Fake The Odyssey movie downloads used to spread malware that targets passwords and crypto wallets

N
News Editor
2026-08-19 10:57:13
Cybersecurity firm Bitdefender has identified multiple fake downloads tied to Christopher Nolan’s new film The Odyssey that were actually delivering Lumma Stealer, a malware strain built to harvest passwords, browser data and cryptocurrency wallet information. The files were disguised as pirated movie releases using labels such as 1080p, 2160p, WEBRip, Blu-ray and H264, with some filenames also including familiar torrent-related terms like EZTV to appear more believable. According to Bitdefender, the supposed movie files were in fact Windows .exe executables. Attackers also disguised the icons as VLC Media Player or generic video files, taking advantage of Windows settings that may hide known file extensions. Once launched, Lumma Stealer can collect saved browser credentials, payment data, autofill records, remote desktop login details and wallet-related information. Browser authentication cookies were also a major target, which could let attackers hijack active sessions even when multi-factor authentication had been enabled. Bitdefender said it confirmed at least three malicious domains connected to the campaign and had blocked them for users of its products. The company also noted that LummaC2, another name for Lumma Stealer, has been linked to at least 1.7 million information-theft incidents and continues to appear in new campaigns despite past law-enforcement action against parts of its infrastructure.

Fake downloads for Christopher Nolan’s new film The Odyssey are being used to distribute Lumma Stealer, malware designed to steal passwords, browser data and cryptocurrency wallet information, according to cybersecurity firm Bitdefender.

Fake The Odyssey movie downloads used to spread malware that targets passwords and crypto wallets 2

Bitdefender said several files circulating online were presented as pirated copies of the movie, but actually contained the information-stealing malware. Researchers found that the filenames were intentionally packed with common piracy tags including 1080p, 2160p, WEBRip, Blu-ray and H264, making them look like high-resolution video releases. Some of the filenames also used familiar torrent keywords such as EZTV to make the downloads appear more legitimate.

The files were not video files at all. They were Windows .exe executables. Attackers also disguised the file icons as VLC Media Player or standard video icons. Combined with Windows settings that may hide known file extensions, that setup could leave users seeing only a movie title and a familiar media icon while missing the fact that the file could execute code.

What the malware is trying to collect

Once a victim runs the fake movie file, Lumma Stealer starts searching the computer for sensitive data. Bitdefender said the malware can steal saved browser usernames and passwords, payment information, autofill data, remote desktop credentials and data tied to cryptocurrency wallets.

Browser authentication cookies were also described as a key target. After a user logs into a site, the browser usually stores session data so the user can stay signed in. If an attacker obtains valid cookies, that attacker may be able to take over an already authenticated session.

That risk does not disappear just because an account has multi-factor authentication enabled. Bitdefender said attackers that obtain a session that has already passed verification may be able to bypass the checks that would normally appear during a fresh login, giving them a path into email accounts, trading platforms and other online services.

Three malicious domains identified

After analyzing the fake The Odyssey files, Bitdefender found that the malware attempted to connect to Lumma Stealer command-and-control infrastructure and confirmed at least three related malicious domains.

The company said it had blocked those domains to prevent users of its products from continuing to connect to them. It also warned that attackers may keep distributing the malware through other filenames, domains and download sources.

LummaC2 remains active despite past disruption efforts

Lumma Stealer, also known as LummaC2, has drawn broad attention in the cybersecurity industry in recent years as an information-stealing malware strain. It has also been offered to other cybercriminals through a Malware-as-a-Service, or MaaS, model, allowing attackers to use ready-made tooling and then choose their own lures, whether films, software or other popular content.

The report noted that U.S. law enforcement had previously taken action against Lumma infrastructure. According to the cited statistics, LummaC2 has been associated with at least 1.7 million information-theft incidents. Even after parts of its infrastructure were disrupted, the malware and its variants have continued to surface across different campaigns.

Movie hype is still being turned into a malware lure

Using popular films to spread malware is a familiar tactic in cybercrime. Researchers have previously documented similar campaigns in which attackers target newly released films that do not yet have official digital versions available, then exploit demand from users searching for terms such as 1080p, Blu-ray or free downloads.

In this case, the method was direct: package malware as the movie file users were already looking for, then add common torrent naming conventions and a VLC-style icon to lower suspicion.

For cryptocurrency holders, the danger is especially direct. Browser extension wallets, exchange login details and other sensitive information are often concentrated on the same computer used every day. Once an infostealer runs successfully, attackers may gain access to both account credentials and wallet-related data at the same time.

Bitdefender advised users not to download files from unknown torrent sources or piracy websites. It also said users can enable full file-extension visibility in Windows. If a file claims to be a video but appears in .exe format, it should be treated as high risk and should not be opened.

The The Odyssey case adds to the evidence that search traffic around popular entertainment releases remains a useful distribution channel for credential-stealing malware.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
20

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.