Cybercriminals are exploiting interest in The Odyssey to distribute Lumma Stealer through fake movie downloads.
Bitdefender researchers identified malicious files posing as pirated copies of Christopher Nolan’s film that instead install the information-stealing malware. Lumma can target browser passwords, authentication cookies, payment information, cryptocurrency wallets, and other sensitive data stored on an infected device.
The campaign uses the rush for pirated copies as its lure: users looking for a free movie download may instead receive an executable designed to look like the file they expected.
How does this campaign work?
According to Bitdefender, several versions of the Lumma Stealer malware are circulating online, disguised as pirated copies of The Odyssey. The observed malware used filenames resembling the release names people would expect for a movie download.
Some of the observed names include:
- the odyssey 2160phd (2026) engsubs eztv.exe
- the odyssey 2026 1080p h264-djt.exe
- the odyssey 2026 1080p webrip-lama.exe

The deception continues at the file level. The executables can use icons associated with legitimate media players such as VLC. At the same time, Windows may hide the .exe extension by default, making a malicious program easier to mistake for an ordinary movie download.
Once a victim runs the file, Lumma Stealer can collect data stored on the infected device. Listed examples include: browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.
Bitdefender also found the malware attempting to communicate with Lumma-associated command-and-control infrastructure, identifying auditva[.]cyou, myroayy[.]cyou, and logmabx[.]click during its analysis.
Why Lumma Stealer?
Lumma Stealer is information-stealing malware developed by a Russian hacking group.
According to Malpedia, the malware is sold through a malware-as-a-service (MaaS) model, meaning criminals can obtain the malware and its supporting infrastructure without having to build their own.
That makes this campaign potentially broader than the samples Bitdefender identified. With Lumma available to multiple operators and The Odyssey inadvertently generating strong demand for pirated copies, different criminals can pair the same malware with different fake downloads. Even Bitdefender warns that its observed samples are not exhaustive.
The campaign illustrates a familiar advantage for cybercriminals: they do not need to compromise a movie studio or streaming platform when they can exploit what users are already searching for.
Major film releases, games, software, and other highly sought-after downloads can provide convincing cover for malicious executables. Attackers only need to make the file look plausible enough for someone to run it.
Users should be particularly cautious when a supposed movie or other media download arrives as an executable file such as .exe. Showing file extensions in Windows, avoiding untrusted download sources, and using security software capable of detecting infostealers can reduce the risk of turning a free download into stolen credentials.
Other News: Researchers uncovered a macOS Screen Sharing authentication flaw that could allow attackers to bypass login protections and gain unauthorized remote access to Macs.