Christopher Nolan's The Odyssey premiered in theaters on July 17, 2026. By August 6, 2026, Bitdefender Labs had documented malicious files masquerading as pirated copies of the film already circulating online. The campaign is not new: it is a copy-paste of the strategy used in 2025 with Mission: Impossible – The Final Reckoning, employing the same malware, the same evasion techniques, and the same objective.
- Bitdefender observed the executable file "the odyssey 2160phd (2026) engsubs eztv.exe" disguised as a pirated copy of the film
- The identified malware is Lumma Stealer, a Russian-origin infostealer that extracts data on first run without requiring persistence
- Windows hides file extensions by default: the user sees only the VLC icon, not the .exe suffix
- The pattern is recycled from the 2025 Mission: Impossible campaign, proving that social engineering on blockbusters works better than technical innovation
How the VLC Icon Trick Works
Attackers customize the icon of executable files to make them resemble VLC Media Player or common video files. The filename observed by Bitdefender — "the odyssey 2160phd (2026) engsubs eztv.exe" — reads like a standard torrent release. On a default Windows installation, however, the .exe extension is not shown. The user sees only the name and the icon.
As Bitdefender noted, "a file ending in .exe may look suspicious under normal circumstances, but someone convinced they're downloading a pirated movie may ignore obvious warning signs." The mechanism does not exploit a zero-day vulnerability; it exploits predictable user behavior on an operating system configured to hide the evidence.
Lumma Stealer and the One-Shot Logic
Recent versions of Lumma Stealer do not use droppers or persistence techniques. Attackers are content with the data collected upon first execution: banking credentials, passwords, cryptocurrency wallets, and sensitive information stored in browsers. The malware identifies itself through communication with known C2 infrastructure, which Bitdefender has already blocked for its users.
The decision to forgo persistence is functional to the campaign. A file that disappears after doing its job leaves fewer diagnostic traces. There is no need to survive a reboot if the target is a home user seeking a film not yet available on legal platforms, willing to dismiss security alerts to view the content.
"These new versions don't come with droppers and persistence techniques. The attackers are content with the data gathered upon execution" — Bitdefender Labs
The Recycled Pattern and the Vulnerability Window
Bitdefender explicitly linked this campaign to a nearly identical pattern documented in 2025: distribution of Lumma Stealer through torrent sites, with files masquerading as Mission: Impossible – The Final Reckoning. The substitution is mechanical: change the blockbuster, keep everything else.
The temporal window is critical. The Odyssey debuted on July 17, 2026; at the time of Bitdefender's report, the film was not available on streaming or digital platforms in many regions. IMAX screenings remained sold out for weeks. This delay between appetite and legitimate availability generates unmet demand that piracy sites intercept.
The campaign requires no sophisticated technical skills. Anyone with access to Lumma Stealer builders and a set of icons can replicate it. The investment is in the timing, not the infrastructure.
What to Do Now
- Enable file extension visibility in Windows: Control Panel > File Explorer Options > View > uncheck "Hide extensions for known file types"
- Verify the true type of any file downloaded from unofficial sources: right-click > Properties, check the "Type of file" field instead of trusting the icon
- Recognize that no legitimate pirated copy has an .exe extension: video containers are .mp4, .mkv, .avi; an executable is always an executable
- On corporate devices under BYOD policy, consider restricting corporate network access for endpoints with outdated or disabled security software
Why Windows Still Hides Extensions
Windows' default configuration that hides extensions is designed to simplify the user experience. In the context of current threats, it produces the opposite effect: it makes benign files and malicious executables indistinguishable. Microsoft has changed other default security behaviors over the years, but this setting persists despite its systematic abuse by malware.
The The Odyssey campaign demonstrates that criminals have no interest in changing strategy. Bitdefender stated the observation precisely: "The latest campaign simply replaces one blockbuster with another. Rather than inventing new attacks, criminals continually recycle successful delivery methods around whatever film is dominating search engines and torrent sites." The innovation, if it can be called that, lies in the film calendar, not the code.
Frequently Asked Questions
Does the malware actually contain the film as a decoy?
The Bitdefender report does not specify whether the .exe files include a video decoy or are pure executables. In any case, the user who runs them does not get to watch the film.
How many users have been infected?
Bitdefender reports that "users have already tried to download" the malicious files, without providing precise figures. Editorial sources claiming "thousands of victims" have no basis in the report's data.
Is the film legally available online?
The Odyssey premiered in theaters on July 17, 2026. Some sources categorically state it is not available on digital platforms; Bitdefender notes that "availability depends on your region." The theatrical exclusivity window persists in most markets.
Information has been verified against cited sources and updated at time of publication.
Sources
- https://www.bitdefender.com/en-us/blog/hotforsecurity/the-odyssey-piracy-lumma-stealer
- https://www.euronews.com/next/2026/08/07/trojan-horse-alert-pirated-online-versions-of-the-odyssey-could-contain-hidden-viruses
- https://ca.news.yahoo.com/trojan-horse-alert-pirated-online-103455157.html
- https://streamlinefeed.co.ke/news/trojan-horse-alert-pirated-online-versions-of-the-odyssey-could-contain-hidden-viruses
- https://www.bitdefender.com/en-au/blog/hotforsecurity/fake-mission-impossible-lumma-stealer-torrent
- https://fr.euronews.com/next/2026/08/07/alerte-cheval-de-troie-copies-pirates-de-the-odyssey-peuvent-cacher-des-virus
- https://de.euronews.com/next/2026/08/07/warnung-vor-trojanern-raubkopien-von-the-odyssey-konnen-malware-enthalten