Criminals are using fake pirated downloads of Christopher Nolan’s “The Odyssey” to trick people into running password-stealing malware. The files look like normal movie downloads (and may even use VLC-style icons), but are actually Windows executables that install Lumma Stealer to grab saved passwords, cookies, payment data, and crypto wallet details.
How the Attack Worked
This attack takes advantage of public interest in a high-profile movie release, 'The Odyssey,' to spread information-stealing malware. Criminals posted files with names designed to look like pirated movie downloads, using naming conventions common to torrent and streaming-rip sites, such as file names referencing resolution and encoding formats. Instead of a video file, the download is a Windows executable. To reinforce the illusion, the executables can use icons associated with legitimate media players such as VLC, and Windows may hide the .exe file extension by default, making the disguise more convincing.
If a person runs the file expecting to watch a movie, the executable instead installs Lumma Stealer. This malware is designed to collect data stored on the infected device, including browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.
Why It Succeeds
The lure works because it targets a normal, low-suspicion activity: downloading a movie people are already curious about. Most users expect a video file, not a program, so an executable disguised with a familiar media player icon and a hidden file extension can bypass casual scrutiny. Because Lumma Stealer is sold as malware-as-a-service, this same tactic can be reused repeatedly by different criminal groups, each generating their own versions of the fake 'Odyssey' files.
What to Watch For
- A movie or media download that arrives as an executable file, such as .exe, rather than a video format
- File names referencing quality or source labels typical of pirated releases, paired with an unexpected .exe ending
- A media player icon (such as VLC) attached to a file from an untrusted or informal download source
- Any prompt to run a program in order to watch a video, rather than opening it directly in a media player
Building Resistance
Organizations and individuals can reduce risk from this type of lure with a few practical habits:
- Avoid downloading pirated or unofficial copies of movies and software, since these sources are commonly used to distribute malware
- Enable the display of file extensions in Windows so a disguised executable is easier to identify before it is run
- Treat any "movie" file that must be run like a program, rather than opened in a media player, as a red flag
- Recognize that stolen browser data can lead quickly to account compromise, so monitor accounts for suspicious logins and consider resetting saved credentials if a device may be infected
This case is a reminder that social engineering does not require a sophisticated pretext. Familiar cultural moments, like a major movie release, are enough to get people to lower their guard and run an unfamiliar file.
Key findings
- Attackers exploit interest in “The Odyssey” by posting fake pirated movie downloads that are actually Lumma Stealer malware.
- The lure relies on users expecting a movie file but receiving a Windows executable designed to look legitimate (including media-player icons and hidden .exe extensions).
- If run, Lumma Stealer can collect browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.
- Bitdefender observed Lumma samples attempting to communicate with Lumma-related command-and-control infrastructure, including auditva[.]cyou, myroayy[.]cyou, and logmabx[.]click.
- Because Lumma is sold as malware-as-a-service, multiple criminals can reuse the same scheme with different “Odyssey” download lures.
Who’s being targeted
- Commonly targeted roles: All employees, IT support/helpdesk, Security awareness training audience.
- Affected industries: General consumers, Media/Entertainment audiences, Any organization whose employees download pirated media on work devices.
- Attack channels: website.
- Impersonated: Pirated release / torrent-style movie listing (e.g., “EZTV”, “WEBRIP” naming).
Red flags to watch for
- The download is an .exe executable rather than a video file (e.g., .mp4/.mkv)
- Windows may hide the .exe extension by default, making it easy to mistake for a media file
- File uses a legitimate-looking media player icon (e.g., VLC) to appear safe
Frequently asked questions
What is the fake 'The Odyssey' download attack?
Attackers post fake pirated movie files for 'The Odyssey' that are actually Windows executables. Running the file installs Lumma Stealer malware instead of playing a movie.
What data can Lumma Stealer steal?
Lumma Stealer can collect browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials from an infected device.
How can I tell if a movie download is actually malware?
Be suspicious if the file is a Windows executable (.exe) instead of a video format like .mp4 or .mkv, since Windows may hide the .exe extension by default and the file may use a legitimate-looking media player icon.
Why is this attack considered malware-as-a-service?
Lumma Stealer is sold as malware-as-a-service, meaning multiple criminals can reuse the same fake movie download scheme with their own variations of the lure.
Read the video transcript
See a free download for Christopher Nolan’s “The Odyssey”? That “movie” might actually be a password-stealing program. Criminals are hiding Lumma Stealer inside fake Odyssey downloads. The file looks like a normal movie, VLC-style cone icon, Windows hiding the .exe, but when you run it, it starts grabbing your browser passwords, cookies, payment data, even crypto wallets. Here’s the trap: you expect an .mp4 or .mkv, but the download is an .exe program. Windows hides the extension, the VLC icon looks legit, and in one double-click Lumma can hijack work accounts through stolen passwords and auth cookies. One move that kills this scam: in Windows, turn on file extensions and never run a “movie” that ends in .exe. If you see that on a download, delete it, don’t touch it.