Hackers are exploiting demand for pirated copies of The Odyssey to spread Lumma Stealer, malware designed to steal passwords, browser sessions and cryptocurrency wallet data. The download may look like a movie release, but the reported file is a Windows application. Opening it runs the malware instead of playing the film.
The scam borrows everything people expect to see in a leaked movie file: the film title, a release year, a resolution such as 1080p or 2160p, an encoding label and a familiar media-player icon. One reported sample used this filename:
The Odyssey 2026 1080p WEBRip-LAMA.exe
The most important part is the final .exe. It identifies the file as a Windows executable, not a video. Attackers count on victims overlooking that suffix or never seeing it because Windows can hide known file extensions.
Malwarebytes found an Odyssey-themed executable carrying a VLC-style orange traffic-cone icon. Windows still identified the file as an application. Its embedded description, “wireless bus Business Controller,” was another warning sign: the metadata had nothing to do with a film or media player.
This is how hackers are weaponizing the movie. They are not altering Christopher Nolan’s film or hiding a wallet drainer inside a normal MP4. They are manufacturing fake movie files that persuade people to launch malware themselves.
How the fake Odyssey movie attack works
CoinMarketCap warned that fake pirated copies of The Odyssey were distributing Lumma Stealer. TechRadar’s report on Bitdefender’s findings described Odyssey-themed executables presented as 1080p, 2160p and H.264 movie releases.
The attack follows a familiar social-engineering chain:
- A victim searches for an unofficial copy of a newly released film.
- A torrent listing or piracy site offers a download with a convincing movie-release name.
- The downloaded file uses a media-player icon, and its
.exeextension may be hidden in File Explorer. - The victim double-clicks the file expecting the movie to start.
- Windows runs Lumma Stealer with the victim’s user access.
- The malware searches the computer for browser credentials, active sessions, wallet data and other information it can send to the attacker.
The reported Odyssey samples did not need an advanced video exploit. The criminals only needed a program that looked enough like a pirated movie to earn a double-click.
The builds examined by Bitdefender reportedly ran without a separate dropper and did not establish persistence. That does not make the infection minor. An information stealer may need only a short window to copy data and send it to attacker infrastructure. Deleting the program later cannot recover passwords, session cookies or wallet secrets that have already left the computer.
Why crypto owners are the target
Lumma Stealer attacks the information that gives a person access to crypto. It does not break Bitcoin or Ethereum cryptography. It searches the infected computer for credentials and wallet material that may let a criminal take control of accounts or sign transactions.
Microsoft’s technical analysis of Lumma says the malware family targets:
- passwords, autofill data and session cookies stored by browsers;
- browser wallet extensions and local data connected to wallets including MetaMask, Electrum and Exodus;
- files in common user folders;
- email, VPN, FTP and Telegram data; and
- system information that helps attackers profile the infected computer.
Microsoft also observed Lumma installing extra malware or plugins, including a clipboard stealer. That type of malware can replace a copied wallet address with one controlled by the attacker. Public reporting has not established that every Odyssey sample used the clipboard plugin, but the capability shows how quickly a stolen download can turn into a crypto loss.
The U.S. Justice Department’s 2025 action against Lumma infrastructure named browser data, banking and email credentials, autofill information and cryptocurrency seed phrases among its common targets. At the time, the FBI had identified at least 1.7 million instances in which LummaC2 was used to steal information.
Different stolen items expose victims in different ways:
- A seed phrase or private key can give an attacker the power to sign transactions and empty the wallet.
- A wallet-extension vault or local wallet file gives the attacker encrypted material that may be combined with other stolen data.
- A session cookie may reopen a logged-in exchange, email or cloud session without requiring the password again.
- A stolen email session can be used to reset exchange accounts or interfere with account recovery.
- A clipboard stealer can redirect a transfer by replacing the destination address.
This is why a fake movie download can lead to stolen crypto even though the malware never attacks the blockchain itself. The compromised computer hands over the credentials and keys used to authorize access.
How hackers make fake movie files look convincing
The Odyssey campaign uses a bare executable disguised as the film, but movie-themed malware can arrive in several forms. The common feature is a file or instruction that persuades the victim to run code.
| What the download looks like | What it actually does |
|---|---|
A movie name ending in .exe or .scr | Windows runs a program when the victim opens it |
A .lnk shortcut presented as a movie launcher | The shortcut can invoke another program, script or command |
| An archive with a “special player” or codec | The victim extracts and launches the bundled executable |
| A large torrent containing a real low-quality video | The decoy video makes the package look believable while a second file carries the malware |
An .mp4, .mkv or .avi file | It is normally video data, though a specially crafted file could target a separate flaw in an outdated player |
Bitdefender documented two earlier Lumma campaigns that show how the packaging changes. A fake Mission: Impossible torrent used an .arj archive containing a self-extracting executable and a multi-stage infection chain. Pirated television torrents found in 2024 included a large .scr screensaver file, which is also executable, alongside a real low-resolution video that made the download size look more plausible.
Icons, filenames and file sizes are easy for an attacker to manipulate. A Windows application can display a media-player icon. A filename can place .mkv or .mp4 in the middle while ending in .exe. A torrent can include screenshots, seed counts or a decoy clip. None of those details proves that the downloaded file is safe.
The fake file is not an infected MP4
A normal MP4 or MKV is a container for encoded video, audio, subtitles and metadata. It is data that a media player parses, while an .exe is a program Windows runs. The Odyssey files described in current reporting fall into the second category.
Specially crafted video files can sometimes exploit security flaws in an outdated media player, codec, thumbnail generator or subtitle parser. VideoLAN has published security bulletins for such flaws, and researchers have previously demonstrated subtitle attacks against vulnerable players. That is a real but separate risk.
There is no public evidence that the Odyssey campaign relies on a new MP4 or MKV vulnerability. Its method is simpler: disguise an executable as a highly anticipated movie and wait for someone to open it.
How to spot a fake movie file
Check the file before opening it:
- Turn on filename extensions. In Windows 11 File Explorer, select View > Show > File name extensions.
- Read the final extension.
Movie.2026.1080p.mkv.exeis an application because.exeis the last suffix. - Check the Type column or Properties. A movie should not appear as an application, Windows shortcut, screensaver, installer, batch file or command script.
- Do not run players or codecs included with a download. Install media software and updates only from the official publisher.
- Inspect everything extracted from an archive. A
.zip,.raror.arjfile can contain executable malware. - Do not trust the icon. Applications can use a VLC-style icon or almost any other image.
- Keep Windows, browsers and media players updated. Patching also reduces the separate risk from malicious files that exploit parser flaws.
Common video extensions include .mp4, .mkv, .mov and .avi. An extension alone cannot prove that a file is harmless. However, a supposed movie ending in .exe, .scr, .lnk, .bat, .cmd, .msi or .com is not a video.
What to do if you downloaded or opened the file
Merely downloading the reported Odyssey executable is different from running it. If the file was downloaded but never opened, delete it without launching it, empty the Recycle Bin, update the computer’s security software and run a scan.
If the file was opened, treat the computer and the secrets stored on it as compromised:
- Disconnect the affected computer from the network.
- Use a different, known-clean device to secure the primary email account first. Then change passwords for exchanges, the password manager, cloud accounts and other important services. Revoke active sessions instead of relying on a password change alone.
- If a seed phrase, private key, browser wallet or software wallet was stored or used on the infected computer, create a fresh wallet with a new recovery phrase on a clean device and move the remaining assets. Do not reuse the old phrase. MetaMask gives the same new-wallet guidance for a compromised wallet.
- Revoke exchange API keys and inspect withdrawal history, login activity, approved devices and withdrawal allowlists.
- Back up required personal documents, not downloaded programs, and rebuild Windows from clean installation media. Antivirus removal cannot prove that passwords or keys were never stolen.
- Monitor wallet addresses and accounts for unauthorized activity. Report any theft promptly to the exchange, wallet provider, relevant law-enforcement channel and insurer where applicable.
Anyone who opened the file on a work computer should contact the organization’s security team before wiping the machine. Investigators may need the logs or a forensic image.
The Odyssey lure works because the filename tells victims what they hope they downloaded while Windows treats the file according to what it really is. In this campaign, that is an executable built to steal information that can unlock crypto wallets and online accounts.
For more wallet-security coverage, see our report on the SafePal customer-data breach and how leaked identity data can feed targeted recovery-phrase scams.
Odyssey fake movie malware FAQ
How are hackers using The Odyssey to steal crypto?
Hackers are distributing Windows executables disguised as pirated copies of The Odyssey. Opening the fake movie launches Lumma Stealer, which targets browser credentials, session cookies, wallet data and other information that can be used to take over accounts or wallets.
Is the fake Odyssey download an infected MP4 or MKV?
No. The publicly reported Odyssey sample ends in .exe and is a Windows application disguised with a movie-release filename and media-player-style icon.
Does a VLC icon mean the file is a video?
No. A Windows executable can carry almost any icon. Show filename extensions and check whether Windows identifies the file as a video or an application.
What can Lumma Stealer take from crypto users?
Microsoft says the malware family targets browser passwords, active sessions, wallet extensions, local wallet data and other files. Some configurations can also install extra malware or clipboard-stealing plugins.
Am I infected if I downloaded the file but did not open it?
The reported executable needs to run for this infection chain to proceed. Delete the file without opening it, update security software and scan the computer.
What should I do if I ran the fake movie?
Disconnect the computer, rotate passwords and revoke sessions from a clean device, replace any exposed wallet seed or private key with a fresh wallet, review exchange access and rebuild the affected computer through a trusted recovery process.
Sources and further reading
- CoinMarketCap: fake Odyssey downloads spreading Lumma Stealer
- TechRadar: Bitdefender’s Odyssey-themed Lumma findings
- Malwarebytes: Odyssey piracy scams and the disguised Windows executable
- Bitdefender: fake Mission: Impossible torrent execution chain
- Bitdefender: pirated TV torrents using SCR files and decoy video
- Microsoft Threat Intelligence: Lumma delivery and information-stealing capabilities
- U.S. Department of Justice: LummaC2 domain seizures and targeted data
- Microsoft Support: showing filename extensions in Windows
- VideoLAN: VLC security bulletins
- Check Point Research: subtitle-parser vulnerabilities in media players
- MetaMask: response steps for a compromised wallet
Security disclosure: This article provides defensive information, not personalized incident-response, legal or financial advice. If a computer that handles material assets or company data may have run an information stealer, use a qualified incident-response professional and rotate exposed wallet secrets from a known-clean device.
Share
Found this useful?
Share it with someone who'd want to read it.
Related

Mac Screen Sharing Flaw Is Being Exploited: Patch CVE-2026-65400 Now
Attackers are exploiting a macOS Screen Sharing authentication flaw on internet-exposed Macs, gaining root access and installing Monero miners. Here is who is at risk, how to patch and what to do after suspected compromise.

Cosmos EVM Hack Explained: How Shared Code Drained Multiple Chains
Attackers used a shared Cosmos EVM flaw to drain KiiChain and TAC and force emergency halts across several networks. The code failed, but so did the warning system around it.

Trump-Linked World Liberty Launches $4B USD1 on Canton
World Liberty Financial's USD1 is now natively issued on Canton, giving tokenized institutional markets another dollar settlement option.
