Pirated 'The Odyssey' Downloads Spread Lumma Stealer Malware Targeting Crypto Wallets

3 hour ago 2 sources negative

Key takeaways:

  • Lumma Stealer's seed-phrase harvesting reinforces hardware wallets as critical for crypto investors.
  • Pirated content lures signal rising malware distribution targeting retail crypto users during film releases.
  • Attackers using BNB Chain smart contracts for CAPTCHA malware show infrastructure is evolving quickly.

A new malware campaign is using pirated copies of the film The Odyssey to spread Lumma Stealer, an information-stealing malware that targets cryptocurrency wallets and sensitive user data. Cybersecurity firm Bitdefender reported on Aug. 6 that researchers found malicious Windows executables disguised as HD WEBRip, 1080p, Blu-ray, and H264 video files. These files use names such as “the odyssey 2160phd (2026) engsubs eztv.exe” and “the odyssey 2026 1080p webrip-lama.exe,” and may show a VLC Media Player icon to hide the .exe extension.

Once executed, Lumma Stealer searches infected computers for browser passwords, saved payment information, autofill records, remote desktop credentials, and cryptocurrency wallet data. It also harvests authentication cookies, which can allow attackers to take over active sessions even when multi-factor authentication is enabled. Bitdefender observed attempts to contact command-and-control infrastructure linked to the malware and identified three domains — auditva[.]cyou, myroayy[.]cyou, and logmabx[.]click — that it blocked for customers. The latest samples did not use separate droppers or persistence tools, unlike a 2025 campaign built around fake copies of Mission: Impossible – The Final Reckoning.

U.S. authorities have previously targeted LummaC2, the malware family behind Lumma Stealer. In May 2025, the Justice Department obtained warrants to seize five internet domains used by administrators, while Microsoft filed a civil case covering about 2,300 related domains. The FBI identified at least 1.7 million cases in which LummaC2 was used to steal information, including crypto seed phrases. Matthew Galeotti, then-head of the Justice Department’s Criminal Division, said such malware is deployed to steal credentials “to facilitate a host of crimes, including fraudulent bank transfers and cryptocurrency theft.”

The Odyssey campaign is part of a broader wave of crypto-focused malware. Microsoft recently found a fake CAPTCHA campaign using BNB Chain smart contracts to deliver Lumma Stealer and other payloads, while researchers have also warned about SparkKitty mobile spyware and the TrapDoor developer-tool campaign. Bitdefender advises users to avoid pirated downloads, enable file extensions in Windows Explorer, keep software updated, and use hardware wallets for cryptocurrency storage.

Disclaimer

The content on this website is provided for information purposes only and does not constitute investment advice, an offer, or professional consultation. Crypto assets are high-risk and volatile — you may lose all funds. Some materials may include summaries and links to third-party sources; we are not responsible for their content or accuracy. Any decisions you make are at your own risk. Coinalertnews recommends independently verifying information and consulting with a professional before making any financial decisions based on this content.