Summary

  • Security firm Bitdefender reported that counterfeit pirated versions of "The Odyssey" have emerged shortly after its release, masquerading as HD movie files but actually containing malware that steals cryptocurrency.
  • The malware also captures authentication cookies, allowing attackers to compromise accounts even with multi-factor authentication enabled, and disguises itself with VLC-like icons.
  • This incident is part of a larger trend where malware is embedded in popular content to target unsuspecting users.

Those attempting to download a pirated version of "The Odyssey" may inadvertently compromise their cryptocurrency wallets.

Bitdefender announced this week that fraudulent downloads of the recently released film are circulating, embedded with Lumma Stealer, a type of malware designed to extract sensitive information, including cryptocurrency wallet data.

According to Bitdefender, these harmful files appeared just days after the film's premiere, disguised as high-definition WEBRip and Blu-ray versions with titles that mimic authentic torrent releases. However, they are actually Windows executable files that infect users' systems instead of delivering a movie.

To enhance the ruse, cybercriminals often replace the icons with those resembling VLC Media Player or video files, exploiting the fact that Windows typically hides file extensions by default, making it difficult for users to distinguish an “.exe” from a genuine video file.

Counterfeit downloads of "The Odyssey" are already being utilized to distribute Lumma Stealer malware. This threat can compromise passwords, browser cookies, and cryptocurrency wallets.
See how Bitdefender Ultimate Security can help protect your digital life:

— Bitdefender (@Bitdefender) August 12, 2026

Once activated, Lumma Stealer extracts browser passwords, saved payment information, autofill data, remote desktop credentials, and cryptocurrency wallets. It also captures authentication cookies, which can allow attackers to access accounts even when multi-factor authentication is in place.

Bitdefender noted that its software successfully blocked these downloads and identified command-and-control domains associated with the operation. The campaign closely resembles a similar one from 2025, which hid the same malware in fake "Mission: Impossible – The Final Reckoning" files.

This situation highlights the regularity with which attackers embed wallet-draining malware within content that users are eager to download.

Over the years, there has been a consistent pattern of similar tactics, including malware hidden in fake CAPTCHA pages routed through BNB Chain, the SparkKitty campaign that inserted wallet-stealing malware into mobile applications, and harmful "anime girl" wallpapers targeting Steam gamers. Attackers have also compromised developer tools by embedding crypto-stealing code in a malicious Python library.

The common factor in these schemes is that the malware is delivered via something the victim actively desires, whether it’s a pirated film, a game modification, or a software package. Bitdefender advises users to utilize legitimate streaming services, avoid executing files marketed as videos, and enable the display of file extensions in Windows to prevent disguised “.exe” files from being mistaken for movies.

Daily Debrief Newsletter

Start every day with the top news stories right now, plus original features, a podcast, videos, and more.