Cybercriminals are exploiting demand for pirated copies of “The Odyssey” by disguising crypto-stealing malware as downloadable versions of the newly released blockbuster.
Cybersecurity firm Bitdefender reported that malicious files began circulating within days of the movie’s release. The downloads are presented as high-definition WEBRip and Blu-ray copies, with filenames designed to resemble legitimate torrent releases.
Instead of containing the movie, however, the files are Windows executables carrying Lumma Stealer, a well-known information-stealing malware capable of extracting sensitive data from infected computers.
Attackers have also reportedly changed file icons to resemble video files or VLC Media Player, making the downloads appear more convincing.
The technique can be particularly effective because Windows hides known file extensions by default, meaning inexperienced users may not immediately notice that what appears to be a movie is actually an executable .exe file.
Fake downloads of The Odyssey are already being used to spread Lumma Stealer malware. This threat can steal passwords, browser cookies, and crypto wallets.
— Bitdefender (@Bitdefender) August 12, 2026
See how Bitdefender Ultimate Security can help protect your digital life:
Fake downloads of The Odyssey are already being used to spread Lumma Stealer malware. This threat can steal passwords, browser cookies, and crypto wallets.
— Bitdefender (@Bitdefender) August 12, 2026
See how Bitdefender Ultimate Security can help protect your digital life:
Malware Targets Crypto Wallets and Passwords
Once executed, Lumma Stealer begins collecting sensitive information stored on the victim's computer.
The malware can target cryptocurrency wallets alongside browser passwords, saved payment information, autofill data and remote desktop credentials.
It can also steal authentication cookies used to maintain logged-in browser sessions. That creates an additional security risk because stolen session cookies can potentially give attackers access to accounts even when multi-factor authentication is enabled.
For cryptocurrency holders, compromised wallet information can be particularly dangerous because blockchain transactions are generally irreversible once funds have been transferred to an attacker-controlled address.
Bitdefender said its security products blocked the malicious downloads and identified command-and-control infrastructure associated with the campaign.
Hackers Recycle an Old Strategy
The campaign is not the first time criminals have exploited demand for newly released movies.
According to Bitdefender, a nearly identical operation appeared in 2025, when malicious downloads disguised as pirated copies of “Mission: Impossible - The Final Reckoning” were used to distribute the same Lumma Stealer malware.
The strategy is straightforward: attackers identify content attracting significant attention and demand, then create malicious downloads designed to capitalize on people searching for free copies.
Movies are only one example. Similar crypto-focused malware campaigns have appeared through mobile applications, gaming content, fake CAPTCHA pages and compromised software packages.
The SparkKitty campaign, for example, targeted cryptocurrency users through malicious mobile applications, while another operation distributed information stealers through anime-themed Wallpaper Engine downloads aimed at Steam users.
Attackers have even targeted software developers by inserting malicious code into compromised programming libraries.
Crypto Malware Hides Behind Popular Content
Despite their different delivery methods, these campaigns share a similar strategy: the victim willingly downloads something they actively want, allowing attackers to bypass some of the suspicion associated with unsolicited files.
Pirated movies provide an attractive opportunity because users may already expect to download unusually large files from unfamiliar websites or peer-to-peer networks.
The use of convincing filenames and familiar media-player icons can make malicious executables look like legitimate video content at first glance.
Once the executable is opened, however, the malware can begin collecting credentials and wallet-related information without delivering the movie the victim expected.
How Users Can Reduce the Risk
Bitdefender recommends using legitimate streaming and distribution services instead of downloading pirated copies from unknown sources.
Users should also avoid opening executable files presented as movies. A genuine video download should not require someone to launch a Windows executable simply to watch the content.
Enabling Windows to display complete file extensions can provide another layer of protection, making it easier to distinguish between a legitimate video format and a disguised .exe file.
The latest campaign highlights a recurring threat for cryptocurrency users: wallet theft increasingly begins outside the wallet itself, with attackers targeting browsers, computers and everyday downloads to obtain the credentials needed to reach digital assets.



