Bitcoin
Bitcoin (BTC)
$64,157.00 1.5
Bitcoin price
Ethereum
Ethereum (ETH)
$1,908.07 1.2
Ethereum price
XRP
XRP (XRP)
$1.00 0.1
XRP price
BNB
BNB (BNB)
$606.78 0.1
BNB price
Solana
Solana (SOL)
$75.93 0.6
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.95 2.8
Hyperliquid price
Cardano
Cardano (ADA)
$0.174343 -1.5
Cardano price
Chainlink
Chainlink (LINK)
$9.51 1.9
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.07894 3.2
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.33 -1.7
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.000061 -2.1
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$64,157.00 1.5
Bitcoin price
Ethereum
Ethereum (ETH)
$1,908.07 1.2
Ethereum price
XRP
XRP (XRP)
$1.00 0.1
XRP price
BNB
BNB (BNB)
$606.78 0.1
BNB price
Solana
Solana (SOL)
$75.93 0.6
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.95 2.8
Hyperliquid price
Cardano
Cardano (ADA)
$0.174343 -1.5
Cardano price
Chainlink
Chainlink (LINK)
$9.51 1.9
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.07894 3.2
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.33 -1.7
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.000061 -2.1
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$64,157.00 1.5
Bitcoin price
Ethereum
Ethereum (ETH)
$1,908.07 1.2
Ethereum price
XRP
XRP (XRP)
$1.00 0.1
XRP price
BNB
BNB (BNB)
$606.78 0.1
BNB price
Solana
Solana (SOL)
$75.93 0.6
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.95 2.8
Hyperliquid price
Cardano
Cardano (ADA)
$0.174343 -1.5
Cardano price
Chainlink
Chainlink (LINK)
$9.51 1.9
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.07894 3.2
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.33 -1.7
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.000061 -2.1
Asteroid Shiba price
Bitcoin
Bitcoin (BTC)
$64,157.00 1.5
Bitcoin price
Ethereum
Ethereum (ETH)
$1,908.07 1.2
Ethereum price
XRP
XRP (XRP)
$1.00 0.1
XRP price
BNB
BNB (BNB)
$606.78 0.1
BNB price
Solana
Solana (SOL)
$75.93 0.6
Solana price
Hyperliquid
Hyperliquid (HYPE)
$58.95 2.8
Hyperliquid price
Cardano
Cardano (ADA)
$0.174343 -1.5
Cardano price
Chainlink
Chainlink (LINK)
$9.51 1.9
Chainlink price
POL (ex-MATIC)
POL (ex-MATIC) (POL)
$0.07894 3.2
POL (ex-MATIC) price
Gram (prev. Toncoin)
Gram (prev. Toncoin) (GRAM)
$1.33 -1.7
Gram (prev. Toncoin) price
Asteroid Shiba
Asteroid Shiba (ASTEROID)
$0.000061 -2.1
Asteroid Shiba price

The Odyssey pirated downloads target crypto wallets

Lawrence Mondal
Edited by
News
The Odyssey pirated downloads target crypto wallets - 1

Fake downloads of The Odyssey have begun spreading Lumma Stealer malware through files disguised as high-quality movie releases, putting crypto wallets, passwords, and browser sessions at risk.

Summary
  • Fake The Odyssey downloads use .exe files disguised as 1080p, WEBRip, and Blu-ray releases.
  • Lumma Stealer can collect crypto wallet data, passwords, payment details, and authentication cookies.
  • Bitdefender blocked malicious downloads and identified three domains connected to the malware.
  • U.S. authorities previously linked LummaC2 to at least 1.7 million information-theft incidents.

Bitdefender reported on Aug. 6 that its researchers had found malicious Windows executables using filenames designed to resemble pirated copies of The Odyssey, only days after the film’s release.

The Odyssey downloads conceal Windows executables

Disguised as video files, the downloads use familiar torrent labels such as 1080p, WEBRip, Blu-ray, and H264 to make the listings appear authentic. Bitdefender identified filenames including “the odyssey 2160phd (2026) engsubs eztv.exe,” “the odyssey 2026 1080p h264-djt.exe,” and “the odyssey 2026 1080p webrip-lama.exe.”

Rather than opening a movie, each .exe file launches software built to infect a Windows computer. Bitdefender said its security products prevented users from downloading or running the detected files, although the researchers warned that other filenames may also be circulating.

Attackers can make the disguise harder to spot by changing the executable’s icon to resemble VLC Media Player or an ordinary video file. Windows installations hide known file extensions by default, according to Bitdefender, which means a user may see a movie-style name and VLC icon without noticing the .exe ending.

People searching torrent sites may also expect unusual filenames, compressed folders, or a bundled video player, giving the malicious file another layer of cover. Bitdefender said the lure does not require a complex trick because the victim has already decided to download an unofficial copy from an unverified source.

Lumma Stealer can capture wallets and browser sessions

Once executed, Lumma Stealer searches the infected computer for browser passwords, saved payment information, autofill records, remote desktop credentials, and cryptocurrency wallet data, according to the security firm.

The malware also collects browser authentication cookies. Bitdefender warned that stolen cookies can let an attacker take over an active account session even when the victim has enabled multi-factor authentication, since the criminal may reuse a session that has already passed the login check.

Known as LummaC2, the malware is an information stealer developed in Russia and sold to other criminals as a service, according to Bitdefender and U.S. authorities. Its availability through underground markets allows buyers to run data-theft campaigns without building their own malware.

During its examination of the Odyssey files, Bitdefender observed attempts to contact command-and-control infrastructure associated with Lumma Stealer. Researchers identified the domains auditva[.]cyou, myroayy[.]cyou and logmabx[.]click, which the company said it had blocked for its customers.

Unlike some earlier versions, the samples found in the latest movie campaign did not use separate droppers or persistence tools, Bitdefender said. The operators instead appeared satisfied with collecting and sending available information during the initial execution.

Previous movie-based Lumma attacks used extra methods to avoid detection. Bitdefender found delayed execution when security software was present, encrypted payload delivery through AutoIt scripts, and other checks in a 2025 campaign built around fake copies of Mission: Impossible – The Final Reckoning.

U.S. agencies previously disrupted LummaC2 infrastructure

For U.S. crypto holders, LummaC2 has already drawn action from federal law enforcement. In May 2025, the Justice Department obtained warrants to seize five internet domains used by the malware’s administrators, while Microsoft filed a separate civil case covering about 2,300 other domains tied to the operation.

Court documents cited by the department said the FBI had identified at least 1.7 million cases in which LummaC2 was used to steal information. Listed targets included browser records, email and bank login details, autofill data, and crypto seed phrases that could provide access to virtual asset wallets.

“Malware like LummaC2 is deployed to steal sensitive information such as user login credentials from millions of victims in order to facilitate a host of crimes, including fraudulent bank transfers and cryptocurrency theft,” Matthew Galeotti, then-head of the Justice Department’s Criminal Division, said in the announcement.

The federal operation seized two domains on May 19, 2025. After LummaC2 administrators told customers about three replacement domains the next day, U.S. authorities seized the new addresses as well, according to the department.

Alongside the seizures, the Cybersecurity and Infrastructure Security Agency and the FBI issued a technical advisory describing how LummaC2 enters computers and removes sensitive information. The Justice Department directed people who believe a device has been compromised to contact the FBI’s Internet Crime Complaint Center or a local field office.

The appearance of new Lumma-linked domains in Bitdefender’s 2026 findings indicates that malware campaigns using the family continued after the 2025 enforcement operation. Bitdefender did not provide a victim count, estimated crypto loss, or geographic breakdown for the Odyssey campaign.

Crypto malware is using familiar content as bait

Movie torrents are one part of a series of malware campaigns that package harmful code inside content, applications, or tools that users actively seek.

Earlier in August, crypto.news reported that Microsoft had found a fake CAPTCHA campaign using BNB Chain smart contracts to retrieve attack instructions. Microsoft said the operation targeted thousands of consumer and business devices each day and delivered several malware families, including Lumma Stealer.

Instead of downloading a movie, people caught in that campaign were instructed to open Windows Run, Terminal, or PowerShell and paste a command supplied by the attacker. Microsoft warned that successful infections could expose credentials, install remote-access tools, and create an entry point for ransomware.

Mobile users have faced a different form of wallet theft. In July, reports renewed attention around SparkKitty mobile malware, which Kaspersky had previously found inside iOS, Android, and third-party applications. The spyware collected images from phone galleries, where some users had stored screenshots of wallet recovery phrases, passwords, and QR codes.

Developer tools have also become a delivery route. Socket disclosed in May that the TrapDoor malware campaign involved at least 34 harmful packages and 384 connected versions across npm, PyPI, and Rust repositories. According to the security company, the packages targeted crypto and artificial intelligence developers while seeking wallet data, GitHub tokens, cloud credentials, and SSH keys.

For the latest movie campaign, Bitdefender advised users to watch films through legitimate streaming services, avoid executables advertised as videos, and keep Windows and security software updated. The company also recommended enabling file extensions in Windows Explorer so an .exe file cannot appear to be an ordinary movie.