Fake ‘The Odyssey’ Downloads Drop Lumma Stealer

TechRepublic Security · Medium sophistication
Last updated August 11, 2026

Criminals are using fake pirated downloads of Christopher Nolan’s “The Odyssey” to trick people into running password-stealing malware. The files look like normal movie downloads (and may even use VLC-style icons), but are actually Windows executables that install Lumma Stealer to grab saved passwords, cookies, payment data, and crypto wallet details.

How the Attack Worked

This attack takes advantage of public interest in a high-profile movie release, 'The Odyssey,' to spread information-stealing malware. Criminals posted files with names designed to look like pirated movie downloads, using naming conventions common to torrent and streaming-rip sites, such as file names referencing resolution and encoding formats. Instead of a video file, the download is a Windows executable. To reinforce the illusion, the executables can use icons associated with legitimate media players such as VLC, and Windows may hide the .exe file extension by default, making the disguise more convincing.

If a person runs the file expecting to watch a movie, the executable instead installs Lumma Stealer. This malware is designed to collect data stored on the infected device, including browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.

Why It Succeeds

The lure works because it targets a normal, low-suspicion activity: downloading a movie people are already curious about. Most users expect a video file, not a program, so an executable disguised with a familiar media player icon and a hidden file extension can bypass casual scrutiny. Because Lumma Stealer is sold as malware-as-a-service, this same tactic can be reused repeatedly by different criminal groups, each generating their own versions of the fake 'Odyssey' files.

What to Watch For

  • A movie or media download that arrives as an executable file, such as .exe, rather than a video format
  • File names referencing quality or source labels typical of pirated releases, paired with an unexpected .exe ending
  • A media player icon (such as VLC) attached to a file from an untrusted or informal download source
  • Any prompt to run a program in order to watch a video, rather than opening it directly in a media player

Building Resistance

Organizations and individuals can reduce risk from this type of lure with a few practical habits:

  • Avoid downloading pirated or unofficial copies of movies and software, since these sources are commonly used to distribute malware
  • Enable the display of file extensions in Windows so a disguised executable is easier to identify before it is run
  • Treat any "movie" file that must be run like a program, rather than opened in a media player, as a red flag
  • Recognize that stolen browser data can lead quickly to account compromise, so monitor accounts for suspicious logins and consider resetting saved credentials if a device may be infected

This case is a reminder that social engineering does not require a sophisticated pretext. Familiar cultural moments, like a major movie release, are enough to get people to lower their guard and run an unfamiliar file.

Key findings

  • Attackers exploit interest in “The Odyssey” by posting fake pirated movie downloads that are actually Lumma Stealer malware.
  • The lure relies on users expecting a movie file but receiving a Windows executable designed to look legitimate (including media-player icons and hidden .exe extensions).
  • If run, Lumma Stealer can collect browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.
  • Bitdefender observed Lumma samples attempting to communicate with Lumma-related command-and-control infrastructure, including auditva[.]cyou, myroayy[.]cyou, and logmabx[.]click.
  • Because Lumma is sold as malware-as-a-service, multiple criminals can reuse the same scheme with different “Odyssey” download lures.

Who’s being targeted

  • Commonly targeted roles: All employees, IT support/helpdesk, Security awareness training audience.
  • Affected industries: General consumers, Media/Entertainment audiences, Any organization whose employees download pirated media on work devices.
  • Attack channels: website.
  • Impersonated: Pirated release / torrent-style movie listing (e.g., “EZTV”, “WEBRIP” naming).

Red flags to watch for

  • The download is an .exe executable rather than a video file (e.g., .mp4/.mkv)
  • Windows may hide the .exe extension by default, making it easy to mistake for a media file
  • File uses a legitimate-looking media player icon (e.g., VLC) to appear safe
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What is the fake 'The Odyssey' download attack?

Attackers post fake pirated movie files for 'The Odyssey' that are actually Windows executables. Running the file installs Lumma Stealer malware instead of playing a movie.

What data can Lumma Stealer steal?

Lumma Stealer can collect browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials from an infected device.

How can I tell if a movie download is actually malware?

Be suspicious if the file is a Windows executable (.exe) instead of a video format like .mp4 or .mkv, since Windows may hide the .exe extension by default and the file may use a legitimate-looking media player icon.

Why is this attack considered malware-as-a-service?

Lumma Stealer is sold as malware-as-a-service, meaning multiple criminals can reuse the same fake movie download scheme with their own variations of the lure.

Read the video transcript

See a free download for Christopher Nolan’s “The Odyssey”? That “movie” might actually be a password-stealing program. Criminals are hiding Lumma Stealer inside fake Odyssey downloads. The file looks like a normal movie, VLC-style cone icon, Windows hiding the .exe, but when you run it, it starts grabbing your browser passwords, cookies, payment data, even crypto wallets. Here’s the trap: you expect an .mp4 or .mkv, but the download is an .exe program. Windows hides the extension, the VLC icon looks legit, and in one double-click Lumma can hijack work accounts through stolen passwords and auth cookies. One move that kills this scam: in Windows, turn on file extensions and never run a “movie” that ends in .exe. If you see that on a download, delete it, don’t touch it.

Similar attacks

Fake Screenshot ZIP Led to DigiCert Cert Theft

Fake Screenshot ZIP Led to DigiCert Cert Theft

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization…

July 17, 2026
Fake Zoom Updates Install ScreenConnect Backdoor

Fake Zoom Updates Install ScreenConnect Backdoor

Researchers describe an active campaign ("SMOKE#SCREEN") where attackers trick users with realistic software update and document-themed lures to install a legitimate remote-control tool (ScreenConnect). Once installed, the attacker gains persistent remote access that can look like normal IT…

August 5, 2026
Phishing Email Pushes Fake Notepad++ Plugin

Phishing Email Pushes Fake Notepad++ Plugin

CERT-UA reported a real phishing campaign where victims receive an email with an image attachment that leads (via a shortened link) to a ZIP download. The ZIP contains a script disguised as a PDF, which installs a malicious Notepad++ plugin and sets up an automated task that repeatedly runs malware…

July 24, 2026
“TTF Trap” Uses Fake Font Files to Drop Malware

“TTF Trap” Uses Fake Font Files to Drop Malware

FortiGuard Labs reports an active phishing operation (“TTF Trap”) where emails posing as invoices, shipping documents, or business proposals deliver an archive that ultimately runs malware on Windows. The trick is a file ending in .ttf (TrueType font) that is actually a malicious script executed by…

July 17, 2026
Fake Zoom/Webex Installers Drop Starland RAT

Fake Zoom/Webex Installers Drop Starland RAT

Cisco Talos reports a real campaign by a Russian-speaking group (UAT-11795) targeting users in the U.S. and Europe with trojanized installers for popular tools like Zoom, Webex, and MobaXterm. Victims are socially engineered via a “ClickFix” style trick into running a command that silently…

July 17, 2026
Phishers Hide Lua Malware as “.TTF Font”

Phishers Hide Lua Malware as “.TTF Font”

A real, ongoing phishing campaign is tricking recipients into opening malicious archives that appear to contain harmless TrueType font files (.ttf) but actually hide a Lua-based loader. Once executed, the loader uses stealthy, mostly in-memory techniques to install remote access trojans and…

July 16, 2026