Pirated 'The Odyssey' Files Distribute Lumma Stealer Malware Targeting Crypto Wallets
Key Takeaways
- •Attackers are disguising Lumma Stealer as fake video files tied to pirated copies of The Odyssey.
- •The malware can collect wallet credentials, browser passwords, payment card details, and authentication cookies from infected devices.
- •Bitdefender warned that stolen session cookies may let attackers bypass multi-factor authentication.
- •For cryptocurrency users, Lumma Stealer can extract private keys and seed phrases, which could give attackers control of funds.
- •Microsoft and the U.S. Department of Justice previously seized about 2,300 domains linked to Lumma’s infrastructure in May 2025.

A new malware campaign is distributing Lumma Stealer, a dangerous infostealer that targets cryptocurrency wallets and other sensitive data, through pirated copies of the film The Odyssey. According to a report by Decrypt, citing cybersecurity firm Bitdefender, attackers disguise executable files as HD WEBRip or Blu-ray video files in order to trick users into running them on their Windows devices. The film — director Christopher Nolan's adaptation of Homer's epic, released theatrically by Universal Pictures in July 2025 — was one of the year's most anticipated releases, and the tactic turns demand for unauthorized copies of a popular film into a channel for stealing sensitive data.
How the Attack Works
Once a user downloads and executes one of these fake video files, the Lumma Stealer malware is installed on the system. The infostealer is designed to harvest a wide range of confidential information from infected machines, including cryptocurrency wallet credentials, browser passwords, payment card details, and authentication cookies. Because stolen session cookies can grant access to almost any logged-in account, the exposure extends well beyond crypto holdings to everyday web services. Lumma, also tracked as LummaC2, is sold as malware-as-a-service, with its operator renting the stealer to affiliates through paid subscriptions advertised on underground forums and Telegram channels — a distribution model that has made it one of the most frequently reported infostealers targeting Windows users. Bitdefender warns that if authentication cookies are compromised, even accounts protected by multi-factor authentication (MFA) could be at risk, as the malware is able to bypass this security layer by stealing session tokens.
Why the Campaign Matters for Crypto Users
For cryptocurrency holders, the threat is particularly severe. Lumma Stealer is capable of extracting private keys and seed phrases from popular wallet applications, giving attackers full control over victims' funds. Unlike phishing attacks that require user interaction, the malware operates silently in the background and often goes undetected by antivirus software. The use of pirated content as a lure is a well-known tactic, but the sophistication of this campaign highlights the evolving nature of modern cyber threats. The malware has already drawn a large-scale response: in May 2025, Microsoft and the U.S. Department of Justice announced coordinated action that seized roughly 2,300 domains tied to Lumma's command-and-control infrastructure, and Bitdefender's findings show the stealer appearing in fresh campaigns such as this one afterward.
Reducing the Risk
To mitigate the risk, users should avoid downloading pirated content from unofficial sources. It is essential to rely on legitimate streaming services or to purchase content from authorized distributors. In addition, maintaining updated antivirus software, enabling real-time protection, and using hardware wallets for cryptocurrency storage can provide an extra layer of security. Regularly reviewing account activity and enabling withdrawal whitelists can also help prevent unauthorized transactions.
Conclusion
This campaign serves as a stark reminder of the dangers associated with pirated media. As cybercriminals continue to refine their methods, staying vigilant and adopting robust security practices is crucial for protecting both personal data and digital assets.
Frequently Asked Questions
What is Lumma Stealer? Lumma Stealer is a type of malware known as an infostealer, designed to collect sensitive information such as passwords, cookies, and cryptocurrency wallet credentials from infected devices.
How does the malware spread through 'The Odyssey' files? Attackers create executable files disguised as video files, often labeled as HD WEBRip or Blu-ray rips of the film. When users download and run these files on a Windows device, the malware is installed on their system.
Can multi-factor authentication protect against Lumma Stealer? While MFA adds a layer of security, Lumma Stealer can steal authentication cookies, which may allow attackers to bypass MFA and gain unauthorized access to accounts.
Source: BitcoinWorld