A new malware campaign is using pirated copies of the film The Odyssey to spread Lumma Stealer, an information-stealing malware that targets cryptocurrency wallets and sensitive user data. Cybersecurity firm Bitdefender reported on Aug. 6 that researchers found malicious Windows executables disguised as HD WEBRip, 1080p, Blu-ray, and H264 video files. These files use names such as “the odyssey 2160phd (2026) engsubs eztv.exe” and “the odyssey 2026 1080p webrip-lama.exe,” and may show a VLC Media Player icon to hide the .exe extension.
Once executed, Lumma Stealer searches infected computers for browser passwords, saved payment information, autofill records, remote desktop credentials, and cryptocurrency wallet data. It also harvests authentication cookies, which can allow attackers to take over active sessions even when multi-factor authentication is enabled. Bitdefender observed attempts to contact command-and-control infrastructure linked to the malware and identified three domains — auditva[.]cyou, myroayy[.]cyou, and logmabx[.]click — that it blocked for customers. The latest samples did not use separate droppers or persistence tools, unlike a 2025 campaign built around fake copies of Mission: Impossible – The Final Reckoning.
U.S. authorities have previously targeted LummaC2, the malware family behind Lumma Stealer. In May 2025, the Justice Department obtained warrants to seize five internet domains used by administrators, while Microsoft filed a civil case covering about 2,300 related domains. The FBI identified at least 1.7 million cases in which LummaC2 was used to steal information, including crypto seed phrases. Matthew Galeotti, then-head of the Justice Department’s Criminal Division, said such malware is deployed to steal credentials “to facilitate a host of crimes, including fraudulent bank transfers and cryptocurrency theft.”
The Odyssey campaign is part of a broader wave of crypto-focused malware. Microsoft recently found a fake CAPTCHA campaign using BNB Chain smart contracts to deliver Lumma Stealer and other payloads, while researchers have also warned about SparkKitty mobile spyware and the TrapDoor developer-tool campaign. Bitdefender advises users to avoid pirated downloads, enable file extensions in Windows Explorer, keep software updated, and use hardware wallets for cryptocurrency storage.