Cybercriminals are distributing the Lumma Stealer malware through Windows executables masquerading as pirated copies of the film The Odyssey (2026) on torrent trackers and piracy sites. Bitdefender Labs published the technical analysis of the campaign on August 6, 2026, revealing a pattern already observed in 2025 with Mission: Impossible – The Final Reckoning. The attack exploits a Windows configuration that has persisted for roughly twenty years: the default setting that hides file extensions.
- Malicious files use names such as 'the odyssey 2026 1080p webrip-lama.exe' and 'the odyssey 2160phd (2026) engsubs eztv.exe', often with a custom icon replicating VLC Media Player
- Windows hides file extensions by default, preventing users from distinguishing an .exe executable from a video container
- Infection installs Lumma Stealer (LummaC2), an info stealer active since 2022 and sold as malware-as-a-service on Telegram channels
- Command-and-control domains auditva[.]cyou, myroayy[.]cyou, and logmabx[.]click have been blocked for users with Bitdefender solutions
How the Trick Works: The Executable That Looks Like a Video
The files identified by Bitdefender Labs contain no movie frames. They are pure Windows executables with the .exe extension, distributed through piracy channels that users normally associate with multimedia content. To complete the deception, operators applied a custom icon reproducing that of VLC Media Player, the widely recognized open-source player.
The decisive element is Windows' default configuration hiding extensions for known file types. A user downloading 'the odyssey 2026 1080p webrip-lama.exe' sees only 'the odyssey 2026 1080p webrip-lama', with the VLC icon alongside. As Hardware Upgrade reported, Rosario Grasso summed up the problem: "A movie is never distributed as an .exe file". Yet the combination of a plausible name, a familiar icon, and an invisible extension removes the warning signals an executable would normally trigger.
Bitdefender Labs documented this same technique in the 2025 campaign tied to Mission: Impossible. The researcher commented: "the same playbook; only the movie has changed". The recurring pattern indicates criminal operators treat cinematic blockbusters as predictable attack cycles, swapping only the thematic wrapper.
LummaC2: The Market for Information Theft
Executing the file installs Lumma Stealer, also known as LummaC2, an info stealer documented since 2022. The malware is sold as a service on Telegram channels accessible to criminal operators, who purchase the infrastructure and distribute it with customized social-engineering techniques.
The malware-as-a-service model lowers the technical barrier to attack: whoever distributes the pirated The Odyssey file does not necessarily develop the payload but buys access to the Lumma platform and configures its collection parameters. The command-and-control domains identified in the campaign — auditva[.]cyou, myroayy[.]cyou, logmabx[.]click — have been blocked for users with Bitdefender solutions, indicating the infrastructure was already cataloged or actively detected.
The brief does not specify the exact nature of data exfiltrated in this campaign. Lumma Stealer is generally associated with theft of browser credentials, session cookies, cryptocurrency wallet data, and authentication information. However, the dossier does not document which of these categories were actually targeted in the The Odyssey variant.
"A file ending in .exe may look suspicious under normal circumstances, but someone convinced they're downloading a pirated movie may ignore obvious warning signs" — Bitdefender Labs
Why Windows Still Hides Extensions, and Why It Matters
Displaying file extensions in Windows requires manual intervention in File Explorer: it is disabled by default in versions of the operating system going back decades. This design choice, aimed at simplifying the user interface, produces a documented security side effect in malware distribution via social engineering spanning at least two decades.
The absence of the .exe extension is not a technical exploit in the classic sense: it exploits no operating-system vulnerability nor parsing bug. It is an abuse of cognitive expectations, where the interface hides a determining property of the digital object. The user does not receive the information needed to correctly classify the file before execution.
The dossier does not document whether Microsoft has ever evaluated changing this default at the system level. The persistence of the configuration across successive Windows releases suggests the priority balance between usability and security transparency has not shifted. For Lumma operators, this equals a stable, reusable attack vector with no additional development cost.
What to Do Now
- Enable file extension display in Windows: File Explorer → View → Show → File name extensions
- Verify that files downloaded from unofficial sources show the full extension before any execution
- Recognize that legitimate video files never use the .exe extension: standard formats are .mp4, .mkv, .avi, .mov
- Consider that custom icons can be modified at the file property level: the VLC icon does not guarantee the nature of the content
The Blockbuster Cycle as an Attack Calendar
The The Odyssey campaign is not an anomaly. It is the re-emergence of a pattern already observed with Mission: Impossible – The Final Reckoning in 2025, with the same malware, same deception technique, same distribution via torrent. The difference is the movie title, not the methodology.
This regularity has implications for defensive planning. Every major cinematic release with sufficient piracy demand generates predictable attack conditions: the user is motivated to ignore risk signals to obtain exclusive content, and the illegal distribution infrastructure offers no integrity verification. For organizations, the risk extends to the corporate perimeter when employees use professional endpoints for personal activities.
The brief does not document specific corrective measures by Microsoft nor regulatory interventions on Lumma distribution. The campaign remains a case of competition between detection speed and reuse of proven techniques, where the novelty lies only in the cultural packaging.
Frequently Asked Questions
Do the malicious files contain at least parts of the movie?
No. The 2026 variants identified by Bitdefender are pure malware, with no movie frames. The deception relies exclusively on the name, the icon, and the hidden extension.
Does Lumma Stealer encrypt files like ransomware?
No. Lumma is an info stealer: it collects sensitive information from the infected system. It does not encrypt files nor demand ransom.
Are the C2 domains still active?
According to the Bitdefender source, the domains had already been blocked for users with its solutions at the time the analysis was published. The dossier does not specify the status for users without these protections.
Sources
- https://www.hwupgrade.it/news/web/download-pirata-di-odissea-attenzione-al-malware-lumma_157881.html
- https://www.bitdefender.com/en-us/blog/hotforsecurity/the-odyssey-piracy-lumma-stealer
- https://www.bitdefender.com/en-au/blog/hotforsecurity/fake-mission-impossible-lumma-stealer-torrent
Information verified against cited sources and current as of publication.