Fake Movie Download Exposes Passwords, Payments, Crypto Assets
Key Takeaways Cybercriminals are distributing Lumma Stealer malware through fake downloads of the movie “The Odyssey (2026).” The malware targets saved browser passwords, payment card...
Key Takeaways
- Cybercriminals are distributing Lumma Stealer malware through fake downloads of the movie “The Odyssey (2026).”
- The malware targets saved browser passwords, payment card details, cryptocurrency wallets, and system credentials.
- Attackers use deceptive filenames and exploit default Windows settings to disguise malicious executables as video files.
- Lumma Stealer is a Russian-developed Malware-as-a-Service (MaaS) that bypasses MFA by harvesting session cookies and active tokens.
Sophisticated Infostealer Campaign Leverages Fake Movie Downloads
In a concerning new campaign, cybercriminals are exploiting the popularity of the recently released film “The Odyssey (2026)” by distributing malicious executables disguised as pirated movie downloads. These files, once executed, deploy Lumma Stealer, a potent information-stealing malware designed to compromise a wide array of sensitive user data.
Table Of Content
The “Odyssey” campaign surfaced quickly after the movie’s theatrical release, with threat researchers observing malicious files circulating on various file-sharing platforms. These files mimic high-quality WEBRip and Blu-ray torrents, luring unsuspecting users into downloading and executing the malware.
Deceptive Tactics and Malware Delivery
Telemetry data from Bitdefender confirms active downloads of these malicious Windows executables. The files are meticulously crafted to appear as legitimate video content, utilizing filenames such as:
the odyssey 2160phd (2026) engsubs eztv.exethe odyssey 2026 1080p h264-djt.exethe odyssey 2026 1080p webrip-lama.exe
Despite their names, these are not media files but compiled binaries engineered to infect endpoints immediately upon execution. This method is not new; it mirrors a 2025 campaign that leveraged fake torrents of “Mission: Impossible The Final Reckoning,” illustrating a common adversary tactic of adapting delivery mechanisms to popular cultural events.
Lumma Stealer: A Potent Threat
Lumma Stealer, also known as LummaC2, is a Russian-developed Malware-as-a-Service (MaaS) offering. Its primary function is to harvest comprehensive data from compromised systems. Upon execution, the malware collects:
- Browser Data: This includes saved login credentials, autofill information, and active authentication cookies from various web browsers.
- Financial Details: Stored credit card numbers and active banking portal sessions are targeted.
- Crypto Wallets: Lumma Stealer seeks out local wallet files and browser extension data for platforms like MetaMask and other cryptocurrency services.
- System Credentials: Remote Desktop Protocol (RDP) login details and local system tokens are also extracted.
A critical capability of Lumma Stealer is its ability to prioritize session cookies and active tokens. This allows attackers to bypass multi-factor authentication (MFA) mechanisms, gaining direct access to sensitive online accounts such as banking portals, email services, and cryptocurrency exchanges.
Research indicates that the operators of Lumma Stealer continuously refine their MaaS toolkit. They incorporate advanced evasion techniques, including delayed execution timers and encrypted delivery scripts, to thwart static detection methods. These sophisticated techniques are frequently adapted across various infostealer malware strains to maximize credential extraction rates.
Bitdefender found that the campaign cleverly exploits user behavior on file-sharing sites. Individuals seeking leaked 1080p or 2160p releases often expect compressed archives and unusual filenames, leading them to rationalize a .exe extension as a custom media player or codec installer.
| Technical Vector | Attack Mechanism | Impact / Evasion Strategy |
| Default OS Settings | Hidden file extensions in Windows Explorer | Disguises .exe files with media player icons (e.g., VLC) |
| Data Exfiltration | Encrypted HTTP POST communication | Sends stolen credential bundles to active C2 servers |
| C2 Infrastructure | Rotating domains (auditva[.]cyou, logmabx[.]click) |
Evades static IP and domain blocklists |

These social engineering patterns are also evident in “clickfix” attack tactics, where users are manipulated into manually executing malicious commands under the guise of technical troubleshooting.
What You Should Do
- Avoid Unofficial Downloads: Strictly refrain from downloading any media, especially new releases, from torrent trackers, unofficial streaming sites, or unverified file-sharing portals.
- Enable File Extensions: Configure your operating system (e.g., Windows File Explorer) to always display full file extensions. This makes it immediately apparent if a file claiming to be a video (e.g.,
.mp4) is actually an executable (.exe). - Never Run Executable Video Files: Treat any file advertised as a movie, media codec, or video player with an
.exeextension as highly suspicious and potentially malicious. Legitimate video files do not require execution. - Deploy Behavioral EDR: For organizations, utilize endpoint detection and response (EDR) solutions equipped with real-time behavioral analysis. These tools can detect and intercept novel malware samples, like Lumma Stealer, before data exfiltration occurs.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.