Fake downloads for Christopher Nolan’s new film The Odyssey are being used to distribute Lumma Stealer, malware designed to steal passwords, browser data and cryptocurrency wallet information, according to cybersecurity firm Bitdefender.

Bitdefender said several files circulating online were presented as pirated copies of the movie, but actually contained the information-stealing malware. Researchers found that the filenames were intentionally packed with common piracy tags including 1080p, 2160p, WEBRip, Blu-ray and H264, making them look like high-resolution video releases. Some of the filenames also used familiar torrent keywords such as EZTV to make the downloads appear more legitimate.
The files were not video files at all. They were Windows .exe executables. Attackers also disguised the file icons as VLC Media Player or standard video icons. Combined with Windows settings that may hide known file extensions, that setup could leave users seeing only a movie title and a familiar media icon while missing the fact that the file could execute code.
What the malware is trying to collect
Once a victim runs the fake movie file, Lumma Stealer starts searching the computer for sensitive data. Bitdefender said the malware can steal saved browser usernames and passwords, payment information, autofill data, remote desktop credentials and data tied to cryptocurrency wallets.
Browser authentication cookies were also described as a key target. After a user logs into a site, the browser usually stores session data so the user can stay signed in. If an attacker obtains valid cookies, that attacker may be able to take over an already authenticated session.
That risk does not disappear just because an account has multi-factor authentication enabled. Bitdefender said attackers that obtain a session that has already passed verification may be able to bypass the checks that would normally appear during a fresh login, giving them a path into email accounts, trading platforms and other online services.
Three malicious domains identified
After analyzing the fake The Odyssey files, Bitdefender found that the malware attempted to connect to Lumma Stealer command-and-control infrastructure and confirmed at least three related malicious domains.
The company said it had blocked those domains to prevent users of its products from continuing to connect to them. It also warned that attackers may keep distributing the malware through other filenames, domains and download sources.
LummaC2 remains active despite past disruption efforts
Lumma Stealer, also known as LummaC2, has drawn broad attention in the cybersecurity industry in recent years as an information-stealing malware strain. It has also been offered to other cybercriminals through a Malware-as-a-Service, or MaaS, model, allowing attackers to use ready-made tooling and then choose their own lures, whether films, software or other popular content.
The report noted that U.S. law enforcement had previously taken action against Lumma infrastructure. According to the cited statistics, LummaC2 has been associated with at least 1.7 million information-theft incidents. Even after parts of its infrastructure were disrupted, the malware and its variants have continued to surface across different campaigns.
Movie hype is still being turned into a malware lure
Using popular films to spread malware is a familiar tactic in cybercrime. Researchers have previously documented similar campaigns in which attackers target newly released films that do not yet have official digital versions available, then exploit demand from users searching for terms such as 1080p, Blu-ray or free downloads.
In this case, the method was direct: package malware as the movie file users were already looking for, then add common torrent naming conventions and a VLC-style icon to lower suspicion.
For cryptocurrency holders, the danger is especially direct. Browser extension wallets, exchange login details and other sensitive information are often concentrated on the same computer used every day. Once an infostealer runs successfully, attackers may gain access to both account credentials and wallet-related data at the same time.
Bitdefender advised users not to download files from unknown torrent sources or piracy websites. It also said users can enable full file-extension visibility in Windows. If a file claims to be a video but appears in .exe format, it should be treated as high risk and should not be opened.
The The Odyssey case adds to the evidence that search traffic around popular entertainment releases remains a useful distribution channel for credential-stealing malware.

