2026-08-17 · digital-assets

Pirated Copies of 'The Odyssey' Are Hiding Crypto-Stealing Malware

In brief

Fans trying to grab an illicit copy of "The Odyssey" may end up handing over their crypto wallets instead.

Security firm Bitdefender said this week that fake pirated downloads of the newly released blockbuster are already circulating loaded with Lumma Stealer, an information-stealing malware that hunts for cryptocurrency wallets among other sensitive data.

According to Bitdefender, the malicious files surfaced within days of the film's launch, disguised as high-definition WEBRip and Blu-ray rips with names mimicking legitimate torrent releases. In reality, they are Windows executables that infect a machine rather than play a movie.

To sell the disguise, attackers often swap in icons resembling VLC Media Player or video files, a trick made more effective because Windows hides file extensions by default, leaving many users unable to tell an ".exe" from an actual video.

Fake downloads of The Odyssey are already being used to spread Lumma Stealer malware. This threat can steal passwords, browser cookies, and crypto wallets.


See how Bitdefender Ultimate Security can help protect your digital life:

— Bitdefender (@Bitdefender) August 12, 2026

Once run, Lumma Stealer scrapes browser passwords, saved payment details, autofill data, remote desktop credentials and crypto wallets. It also lifts authentication cookies, meaning victims can lose access to accounts even with multi-factor authentication switched on.

Bitdefender said its products blocked the downloads and flagged command-and-control domains tied to the operation, and noted the campaign mirrors a near-identical one in 2025 that hid the same malware inside fake "Mission: Impossible – The Final Reckoning" files.

The findings underscore how routinely attackers now bury wallet-draining code inside content people are eager to download.

Over the years, there has been a steady drumbeat of similar schemes, including malware smuggled through fake CAPTCHA pages routed via BNB Chain, the SparkKitty campaign that slipped wallet-stealing code into mobile apps, and malicious "anime girl" wallpapers aimed at Steam gamers. Attackers have also poisoned developer tooling, planting crypto-stealing code inside a booby-trapped Python library.

The common thread is that the malware rides in on something the victim actively wants, whether a pirated film, a game mod or a coding package. Bitdefender's advice is blunt: stick to legitimate streaming services, never run an executable advertised as a video, and enable Windows' file-extension display so a disguised ".exe" can't pass as a movie.

More stories