Nothing says “summer blockbuster season” quite like cybercriminals racing to exploit your movie habits. Bitdefender researchers disclosed on August 6 that fake pirated copies of The Odyssey, the 2026 theatrical release, are being used to distribute Lumma Stealer, a particularly nasty strain of information-stealing malware that targets crypto wallets, saved passwords, payment details, and browser session cookies.
The malicious files are disguised as high-resolution video downloads, complete with filenames designed to look legitimate to anyone familiar with piracy scene conventions. Think formats like “the odyssey 2160phd (2026) engsubs eztv.exe” that mimic popular release groups and encoding standards. The telltale giveaway is the .exe extension, which no legitimate video file would carry, but the attackers even dress the executable icons to resemble VLC media player to reduce suspicion.
How Lumma Stealer actually works
Lumma Stealer is not new, but it keeps evolving. The malware targets Windows systems and, once executed, silently harvests a buffet of sensitive data from the infected machine. Browser passwords, autofill data, payment card numbers stored in Chrome or Edge, and cryptocurrency wallet credentials all get scraped and exfiltrated.
What makes Lumma particularly dangerous for crypto holders is its ability to steal session cookies. That matters because session cookies can be used to bypass two-factor authentication entirely. An attacker doesn’t need your password or your authenticator app if they can simply replay your active browser session on an exchange or wallet interface.
Bitdefender’s analysis identified several command-and-control domains the malware communicates with, including auditva[.]cyou and logmabx[.]click. Both domains were already flagged and blocked by Bitdefender’s security products at the time of the advisory, which means users running updated endpoint protection were shielded.
A malware strain that refuses to stay dead
In May 2025, law enforcement conducted a significant takedown operation that neutralized roughly 2,300 domains associated with the malware’s infrastructure. The malware resurfaced, rebuilt its infrastructure, and found new distribution vectors. Pirated movie downloads are just the latest channel. Previous campaigns have used cracked software, fake CAPTCHA pages, and phishing emails to deliver the payload.
Lumma operates on a malware-as-a-service model, meaning the developers license the stealer to other criminals who then choose their own distribution methods. Take down one distributor’s infrastructure and another pops up with a fresh campaign.
Why crypto users should pay attention
Lumma Stealer explicitly targets browser-based wallet extensions and locally stored wallet data. MetaMask, Phantom, and similar browser wallets are prime targets because they store encrypted vault data locally. If the malware can extract that data along with the decryption key from memory or cached credentials, the wallet is compromised.
Even hardware wallet users aren’t entirely safe if they use browser-based interfaces to interact with their devices. A stolen session cookie from a DeFi protocol’s front end could allow an attacker to queue malicious transactions that the user might unknowingly approve on their hardware device during a routine signing session.
The fact that Lumma Stealer bounced back from a 2,300-domain takedown in roughly a year suggests this threat isn’t going away, and each new blockbuster release gives its operators fresh social engineering ammunition to work with.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 day ago
21








English (US) ·