
According to reports from Bitdefender, researchers discovered malicious Windows executables disguised as pirated copies of The Odyssey movie, targeting users just days after the film's release. The fake downloads use familiar torrent labels such as 1080p, WEBRip, Blu-ray, and H264 to appear authentic. Bitdefender identified specific filenames including 'the odyssey 2160phd (2026) engsubs eztv.exe', 'the odyssey 2026 1080p h264-djt.exe', and 'the odyssey 2026 1080p webrip-lama.exe'. Rather than opening a movie, each .exe file launches software designed to infect Windows computers, with Bitdefender's security products preventing users from downloading or running the detected files.
As reported by Bitdefender, once executed, Lumma Stealer searches infected computers for sensitive information including browser passwords, saved payment information, autofill records, remote desktop credentials, and cryptocurrency wallet data. The malware also collects browser authentication cookies, which can allow attackers to take over active account sessions even when multi-factor authentication is enabled. According to Bitdefender, the malware is an information stealer developed in Russia and sold as a service through underground markets, allowing buyers to run data-theft campaigns without building their own malware infrastructure.
According to Bitdefender's August 6 report, researchers identified three domains connected to the malware campaign: auditva[.]cyou, myroayy[.]cyou, and logmabx[.]click. The company blocked these domains for its customers during the investigation. Unlike previous versions, the latest samples found in the movie campaign did not use separate droppers or persistence tools, with operators instead collecting available information during initial execution. Previous Lumma campaigns used more sophisticated methods including delayed execution when security software was present and encrypted payload delivery through AutoIt scripts.
As reported by the Justice Department, in May 2025, federal authorities obtained warrants to seize five internet domains used by LummaC2 administrators, while Microsoft filed a separate civil case covering approximately 2,300 other domains tied to the operation. Court documents cited by the department indicated that the FBI had identified at least 1.7 million cases in which LummaC2 was used to steal information, with listed targets including browser records, email and bank login details, autofill data, and crypto seed phrases. The federal operation seized two domains on May 19, 2025, with authorities seizing replacement domains the following day after LummaC2 administrators informed customers of new addresses.
According to Bitdefender's guidance, users should watch films through legitimate streaming services and avoid executables advertised as videos. The company recommends keeping Windows and security software updated, enabling file extensions in Windows Explorer to prevent .exe files from appearing as ordinary movies, and using legitimate torrent sites with verified downloads. The security firm noted that the lure does not require complex tricks since victims have already decided to download unofficial copies from unverified sources.