Cybersecurity firm Bitdefender says fake pirated copies of The Odyssey are being distributed online as supposed high-definition WEBRip and Blu-ray files, but the downloads are actually Windows executables designed to install Lumma Stealer.
According to the company, the malware targets cryptocurrency wallets along with other sensitive information stored on a victim’s device. It can also steal authentication cookies, which may let attackers take over accounts even when multi-factor authentication is enabled.
Disguised as video files
Bitdefender said the malicious files are being presented as movie rips to attract people looking for unauthorized copies of the film. Instead of video content, the files launch Lumma Stealer when opened on Windows systems.
The company said the campaign uses icons that resemble VLC Media Player or ordinary video files, a tactic meant to fool users who cannot see full file extensions. That can make an executable appear similar to a media download at a glance.
What the malware is built to collect
Once executed, Lumma Stealer attempts to harvest a wide range of stored data. Bitdefender said the malware scrapes browser passwords, saved payment details, autofill information, remote desktop credentials, and cryptocurrency wallets.
The theft of authentication cookies is a particularly serious part of the attack. Because those cookies can keep a session authenticated, attackers may be able to hijack accounts without needing to pass the victim’s multi-factor login checks again.
Part of a familiar pattern
Bitdefender said its security products blocked the malicious downloads and detected associated command-and-control domains linked to the operation.
The company also said the activity closely resembles a 2025 campaign that used fake files for Mission: Impossible – The Final Reckoning to spread the same Lumma Stealer malware. The comparison suggests criminals are reusing a proven method: hiding information-stealing code inside files tied to highly sought-after entertainment content.
Advice and next steps
Bitdefender’s guidance is straightforward: use legitimate streaming services, avoid running any executable presented as a video file, and turn on Windows’ file-extension display so disguised programs are easier to spot.
The company’s findings add to a broader pattern it says is now common, with attackers embedding wallet- and credential-stealing malware inside content that users actively want to download, whether that is a pirated film, a game modification, or a software package.
Source: decrypt.co