Odyssey fake torrents spread Lumma Stealer to crypto wallets
Security firm Bitdefender says fake “The Odyssey” movie downloads are being used to deliver Lumma Stealer malware to unsuspecting users and put crypto wallets at risk. The lure uses common torrent-style labels like “1080p”, “WEBRip”, “Blu-ray”, and “H264”, but the listings actually distribute Windows .exe files disguised as video releases.
Bitdefender identified sample filenames such as “the odyssey 2026 1080p h264-djt.exe” and “the odyssey 2026 1080p webrip-lama.exe”. The malware then searches for browser passwords, saved payment details, remote desktop credentials, and cryptocurrency wallet data, along with browser authentication cookies. LummaC2 can reuse stolen session cookies, potentially bypassing multi-factor authentication.
Bitdefender also reported contacting command-and-control domains linked to the campaign and blocked three domains: auditva[.]cyou, myroayy[.]cyou, and logmabx[.]click. The company said the newer campaign does not rely on the same extra dropper/persistence techniques seen in earlier Lumma operations.
For context, U.S. authorities previously targeted the LummaC2 infrastructure: in May 2025 the Justice Department obtained warrants to seize domains used by administrators, and court filings cited at least 1.7 million information-theft incidents involving LummaC2, including theft of crypto seed phrases.
Bitdefender advises users to avoid executing “video” downloads that are actually executables, watch content via legitimate streaming services, keep Windows/security tools updated, and enable file extensions in Windows Explorer so .exe cannot be hidden.
Neutral
This is primarily an endpoint and fraud risk event, not a protocol change or on-chain disruption. While Lumma Stealer targeting crypto wallets can trigger short-term retail fear and lead to incremental sell pressure from victims or cautious users, it does not directly affect network throughput, liquidity, or major market fundamentals. Historically, large malware campaigns tied to popular content (e.g., fake downloads or fake developer tools) tend to produce brief attention spikes and volatility in affected coins if news spreads widely, but market impact usually fades once prevention guidance and domain takedowns roll out.
In the short term, traders may see minor sentiment drag and higher caution around self-custody practices (wallet hygiene, session/cookie risk awareness). In the long term, the continued appearance of LummaC2 domains after previous U.S. enforcement suggests the threat persists, but it is unlikely to systematically destabilize broader crypto prices. Net effect: mostly neutral for market stability.