
Only days after The Odyssey became one of the biggest movie launches of the year, cybersecurity researchers have already observed fake pirated copies distributing the Lumma Stealer malware. Internal Bitdefender insights show that users have already tried to download malicious executables disguised as the movie.
Every major movie release attracts countless searches from people hoping to watch it before it becomes widely available—and even before the official release in its digital form. Cybercriminals understand this better than anyone and are always prepared with new builds.
Bitdefender researchers have already observed malicious files disguised as The Odyssey (2026) circulating online. According to internal insights, Bitdefender security solutions prevented users from downloading and executing malicious files.
Several lure filenames were observed, including:
These downloads are actually Windows executables designed to infect the victim instead of play a video. Keep in mind that this list is not exhaustive— criminals likely use many other file names.
This isn't a new technique. In 2025, researchers documented an almost identical campaign abusing fake downloads of Mission: Impossible – The Final Reckoning, where attackers distributed Lumma Stealer through torrent websites using files disguised as movie releases.
The latest campaign simply replaces one blockbuster with another. Rather than inventing new attacks, criminals continually recycle successful delivery methods around whatever film is dominating search engines and torrent sites.
And it’s worth noting that torrent trackers are chock-full of this type of malware. Popular movies are not the only ones being used to spread Lumma and other stealers. The same goes for TV shows and cracked games and software.
Lumma Stealer has become one of today's most widespread information stealers. Also known as LummaC2, it is a Russian-developed info stealer malware that has gained popularity among cybercriminals by promising quick results and ease of use.
Once executed, it can harvest:
Because the malware steals browser session cookies, victims may lose access to accounts even when multi-factor authentication is enabled.
The malware seen in previous movie campaigns also employed multiple evasion techniques, including delayed execution when security software was detected and encrypted payload delivery through AutoIt scripts.
Interestingly, these new versions don’t come with droppers and persistence techniques. The attackers are content with the data gathered upon execution.
Another interesting aspect of this campaign is how little social engineering is required. People searching for leaked copies of highly anticipated movies are already imagining unusual filenames, compressed archives or unofficial download sources.
A file ending in .exe may look suspicious under normal circumstances, but someone convinced they're downloading a pirated movie may ignore obvious warning signs if they believe it contains a video player or installer.
Security researchers also noted that criminals often customize executable icons to resemble VLC Media Player or common video files, making the malware appear more legitimate.
In fact, for the default Windows installation, file extensions are not shown by default. If a user doesn’t activate this option manually, there’s no way to visually determine if a file is an executable or a media file. The user only sees the VLC icon.

During analysis, researchers identified the malware attempting to communicate with infrastructure associated with Lumma Stealer.
Among the domains observed were:
The infrastructure was already blocked, preventing successful communication for anyone running Bitdefender security solutions.
If you want to avoid becoming the next victim:
Fake movie downloads are only one of many ways cybercriminals distribute information stealers. Bitdefender Ultimate Security combines advanced behavioral detection, anti-phishing protection, ransomware defense and identity protection to stop threats like Lumma Stealer before they can steal passwords, browser sessions and cryptocurrency wallets.
Availability depends on your region and official distribution schedule. Be cautious of unofficial downloads claiming to offer free copies immediately after release.
A genuine video file cannot execute code by itself. However, attackers often disguise Windows executables as movie downloads.
Lumma Stealer is an information-stealing malware family designed to steal passwords, browser cookies, cryptocurrency wallets and other sensitive data.
Major releases generate millions of searches, allowing criminals to hide malicious downloads among legitimate discussions and torrent listings.
Modern security solutions using behavioral detection can often stop Lumma before it completes its infection, even when the sample is newly compiled.
This article is published for informational and educational purposes only. The information presented is based on technical research conducted by Bitdefender Labs and publicly available sources. Bitdefender does not make any legal determination regarding the activities described herein. The mention of any company, brand, domain, or individual does not constitute an accusation of illegal activity. Readers should exercise their own judgment and consult appropriate authorities or legal counsel if they believe they have been affected by any of the activities described. Domain names and URLs listed in this article are provided solely to help consumers and security professionals identify potentially harmful infrastructure. Bitdefender disclaims any liability for actions taken based on the information in this article.
tags
Silviu is a seasoned writer who followed the technology world for almost two decades, covering topics ranging from software to hardware and everything in between.
View all posts