- A major cybersecurity firm warns that many pirated copies of Christopher Nolan’s The Odyssey may be embedded with malware that attacks crypto wallets.
Christopher Nolan’s rendition of Homer’s The Odyssey is now a certified box office success. After a domestic opening of over $123.5 million on July 17 across US theaters, ticket sales are now nearing $1.3 billion globally. It comes against the film’s $250 million budget per Box Office Mojo.
With the persistent issue of movie piracy behind the scenes, many argue that the numbers could have been higher. Despite the film still exclusively available in theaters, with Universal Pictures yet to announce its launch on streaming platforms, some copies of the film are already making their rounds online.
Malware Threat in Pirated Copies of The Odyssey
Bitdefender, a cybersecurity app provider, warned that hackers have taken advantage of The Odyssey’s popularity to install malware into versions of the film available on piracy sites. One of the most common malicious executables embedded into their files is the Lumma Stealer.
Among the most common lure filenames Lumma Stealer uses to trick unsuspecting downloaders are:
- the odyssey 2160phd (2026) engsubs eztv.exe
- the odyssey 2026 1080p h264-djt.exe
- the odyssey 2026 1080p webrip-lama.exe
The cybersecurity firm noted that there are many other variations of the malicious executable. Meanwhile, it highlighted that the technique Lumma Stealer employs is no longer new. However, it remains a persistent threat on piracy sites, which eventually find their way to unsuspecting victims.
Once executed, Lumma Stealer harvests the infected system’s browser history and autofill data, passwords, authentication cookies, saved payment information, stored crypto wallet seed phrases and private keys, and other critical details. What’s more, it could result in victims losing access to their accounts even when multi-factor authentication is enabled.
Besides pirated movies, Lumma Stealer can be found on stolen copies of software and video games.
Key Features of Lumma Stealer
Microsoft classifies Lumma Stealer, also known as LummaC2, as a malware-as-a-service (MaaS) offering. It’s capable of bypassing a device’s apps and browsers to steal login credentials and other personal information connected with them.
The malware particularly targets crypto wallets to steal funds from victims’ devices. In addition to direct injection into files, malicious actors typically package it with their phishing and malvertising campaigns. Moreover, they use it to exploit vulnerabilities on trusted platforms and traffic distribution systems.
Microsoft claimed that the threat actor maintaining the Lumma Stealer ecosystem, consisting of malware, command-and-control (C2) infrastructure, and the Lumma MaaS, goes by the alias Storm-2477. The pseudonymous hacker reportedly offers the MaaS platform to high-stakes ransomware threat actors, such as Octo Tempest, who prey on high-profile individuals and enterprise infrastructure.







