Fake Movie Downloads Spread Lumma Stealer Malware

Cybercriminals are exploiting the popularity of the recent blockbuster “The Odyssey (2026)” to distribute Lumma Stealer, a potent information-stealing malware. This malicious software infiltrates systems through pirated movie downloads, compromising sensitive data such as saved browser passwords, payment card details, and cryptocurrency wallets.

Shortly after “The Odyssey” became a highly anticipated release, threat researchers identified malicious executables disguised as high-quality WEBRip and Blu-ray torrents on various file-sharing platforms. These deceptive files, bearing names like “the odyssey 2160phd (2026) engsubs eztv.exe” and “the odyssey 2026 1080p h264-djt.exe,” are not media files but compiled binaries designed to infect systems upon execution.

This tactic mirrors previous campaigns, such as the 2025 incident involving fake “Mission: Impossible The Final Reckoning” torrents, highlighting a recurring strategy where attackers leverage trending box-office titles to lure victims.

Understanding Lumma Stealer

Lumma Stealer, also known as LummaC2, is a Russian-developed Malware-as-a-Service (MaaS) that, once executed, harvests a wide range of sensitive information, including:

  • Browser Data: Saved login credentials, autofill records, and active authentication cookies.
  • Financial Details: Stored credit card information and banking portal sessions.
  • Crypto Wallets: Local wallet files and browser extensions for platforms like MetaMask.
  • System Credentials: Remote Desktop Protocol (RDP) login details and local system tokens.

By prioritizing session cookies and active tokens, Lumma Stealer enables attackers to bypass multi-factor authentication (MFA) challenges, granting direct access to online banking, email accounts, and cryptocurrency exchanges.

The operators of Lumma Stealer continuously refine their toolkit with features like delayed execution timers and encrypted delivery scripts to evade static detection methods. This adaptability is a common trait among various information-stealing malware strains, enhancing their effectiveness in credential extraction.

Exploitation Tactics

The campaign exploits user behavior on file-sharing sites, where individuals seeking leaked 1080p or 2160p releases often encounter compressed archives and unusual filenames. Victims may rationalize an “.exe” extension as a custom media player or codec installer, inadvertently executing the malware.

Technical vectors employed in this campaign include:

  • Default OS Settings: Hidden file extensions in Windows Explorer disguise “.exe” files with media player icons, such as VLC.
  • Data Exfiltration: Encrypted HTTP POST communication sends stolen credential bundles to active command-and-control (C2) servers.
  • C2 Infrastructure: Rotating domains (e.g., auditva[.]cyou, logmabx[.]click) help evade static IP and domain blocklists.

Similar social-engineering patterns appear in other attack tactics, where users are tricked into manually triggering malicious commands under the guise of technical troubleshooting.

Protective Measures

To safeguard against movie-themed malware campaigns, both security teams and individual users should implement the following practices:

  • Avoid Unofficial Downloads: Refrain from downloading pirated media from torrent trackers or unverified file-sharing portals.
  • Enable File Extensions: Configure Windows File Explorer to display full file extensions, making “.exe” files masquerading as videos immediately visible.
  • Never Run Video “.exe” Files: Treat any executable advertised as a movie, media codec, or video player as potentially malicious software.
  • Deploy Behavioral Endpoint Detection and Response (EDR): Utilize endpoint security tools equipped with real-time behavioral analysis to intercept zero-day Lumma samples before data exfiltration occurs.

As cybercriminals continue to exploit popular media releases to distribute malware, it is crucial for users to exercise caution and adhere to best practices when downloading content. Staying vigilant and informed can significantly reduce the risk of falling victim to such deceptive campaigns.