VYPR
researchPublished Aug 6, 2026· 1 source

Fake Movie Downloads Deliver Lumma Stealer, Targeting Passwords and Crypto

Cybercriminals are distributing Lumma Stealer via pirated downloads of the movie 'The Odyssey (2026)', aiming to steal saved passwords, payment card details, and cryptocurrency assets.

Cybercriminals are exploiting the popularity of the new film "The Odyssey (2026)" by distributing the Lumma Stealer malware through fake movie downloads on file-sharing platforms. These malicious executables, disguised as high-quality WEBRip and Blu-ray torrents, are designed to infect user systems upon execution and steal a wide range of sensitive information.

Threat researchers have observed threat actors using deceptive filenames such as "the odyssey 2160phd (2026) engsubs eztv.exe" and "the odyssey 2026 1080p h264-djt.exe" to trick users into downloading and running malware instead of the intended movie files. This tactic mirrors previous campaigns that leveraged trending movie releases, such as "Mission: Impossible The Final Reckoning," to distribute malware, highlighting a persistent social engineering strategy.

Lumma Stealer, a prolific information-stealing malware family often tracked as LummaC2 and developed in Russia, is a Malware-as-a-Service (MaaS) offering. Once executed, the malware systematically harvests critical data from compromised systems. This includes saved login credentials, autofill data, and active authentication cookies from web browsers, as well as stored credit card information and banking session details.

Beyond financial and web credentials, Lumma Stealer also targets cryptocurrency assets. It is capable of stealing local wallet files and browser extensions associated with popular platforms like MetaMask. Furthermore, the malware can exfiltrate system credentials, including Remote Desktop Protocol (RDP) login details and local system tokens, broadening the scope of potential compromise.

A particularly concerning capability of Lumma Stealer is its ability to bypass multi-factor authentication (MFA). By harvesting session cookies and active authentication tokens, attackers can gain direct access to sensitive online accounts, including email, banking portals, and cryptocurrency exchanges, without needing to overcome MFA challenges.

The operators behind Lumma Stealer continuously refine their MaaS toolkit to evade detection. Techniques such as delayed execution timers and encrypted delivery scripts are employed to defeat static security measures. These adaptations are common among various infostealer malware strains, aiming to maximize the success rate of credential extraction.

Bitdefender's analysis indicates that this campaign capitalizes on user behavior on file-sharing sites, where users accustomed to compressed archives and unusual filenames may overlook the malicious nature of an .exe file, often rationalizing it as a necessary codec or player installer. To mitigate these risks, users are advised to avoid unofficial downloads, enable file extensions in their operating systems to easily spot .exe files, and treat any executable masquerading as media content as malicious.

Implementing robust endpoint security solutions with real-time behavioral analysis is crucial for intercepting new Lumma samples before they can exfiltrate data. This layered approach, combined with user education on safe downloading practices, is essential for defending against such evolving malware distribution tactics.

Synthesized by Vypr AI