Headline: Pirates or pickpockets? Fake downloads of The Odyssey are spreading Lumma Stealer and draining crypto wallets Bitdefender researchers say threat actors are disguising Lumma Stealer inside fake Windows "movie" downloads for the newly released film The Odyssey, putting crypto wallets, passwords and active browser sessions at risk. What’s happening - On Aug. 6 Bitdefender flagged multiple .exe files mimicking high-quality pirate releases (filenames such as “the odyssey 2160phd (2026) engsubs eztv.exe,” “the odyssey 2026 1080p h264-djt.exe,” and “the odyssey 2026 1080p webrip-lama.exe”). Instead of video players, the files run Lumma Stealer malware on Windows PCs. - Attackers make the fraud harder to spot by changing the executable’s icon to look like VLC or a video file, while Windows’ default setting hides known file extensions so victims may not see the “.exe” suffix. - Bitdefender said its products blocked the detected samples for customers but warned other malicious filenames and domains are likely circulating. What Lumma steals and why crypto holders should care - Lumma Stealer (also tracked as LummaC2) harvests browser-stored passwords, saved payment details, autofill records, remote-desktop credentials and cryptocurrency wallet data — including seed phrases and private keys when present. - The malware also exfiltrates browser authentication cookies. Stolen cookies can let attackers hijack active sessions even when multi-factor authentication is enabled, because the session may already have passed the login step. - Bitdefender observed the Odyssey samples attempting to contact command-and-control domains (auditva[.]cyou, myroayy[.]cyou, logmabx[.]click), which the company has blocked for customers. Background and law-enforcement action - Bitdefender and U.S. authorities say LummaC2 is a Russian-developed information stealer sold as malware-as-a-service on underground markets, letting buyers run data-theft campaigns without building their own tooling. - The Justice Department and Microsoft took enforcement action in May 2025: DOJ obtained warrants to seize five domains used by the operation and later seized replacement domains; Microsoft filed a civil case covering roughly 2,300 additional domains. - Court filings cited by DOJ said the FBI identified at least 1.7 million instances in which LummaC2 was used to steal credentials, browser data and crypto seed phrases. - Unlike some earlier movie-themed campaigns, the latest Odyssey samples did not use separate droppers or persistence tricks — the operators appeared to focus on collecting and exfiltrating data during first execution. Broader context — multiple delivery routes targeting wallets - Movie torrents are just one baiting tactic. Security firms have also tracked: - Fake CAPTCHA campaigns that used BNB Chain smart contracts to pull down attacker commands and install multiple malware families, including Lumma. - Mobile spyware like SparkKitty that scrapes phone galleries for screenshots of recovery phrases, QR codes and passwords. - Supply-chain attacks against developer repositories (TrapDoor) that pushed malicious npm, PyPI and Rust packages to steal wallets, tokens, cloud creds and SSH keys. What you should do - Avoid downloading movies, apps or tools from unverified sources or torrent sites. - Never run executables advertised as videos. Enable file extensions in Windows Explorer so .exe files are visible. - Keep Windows and security software up to date and use reputable endpoint protection. - If you suspect a device is compromised, follow guidance from law enforcement/your security vendor; U.S. authorities advised contacting the FBI’s Internet Crime Complaint Center or local field office. Bitdefender did not provide a victim count, estimated crypto losses or geographic breakdown for this Odyssey campaign, but the incident is another reminder that simple download habits can expose crypto assets — and that attackers continue to adapt their lures. Read more AI-generated news on: undefined/news