Pirated digital copies of the blockbuster film “Odyssey” are being exploited to compromise viewers’ computers, according to a recent study by cybersecurity firm Bitdefender.
Internal data from Bitdefender indicates that users have already attempted to download malicious executable files disguised as the film. “Odyssey” has not yet been released on online platforms, and IMAX screenings in most theaters remain sold out for weeks ahead.
Just days after “Odyssey” became one of the year’s biggest cinematic releases, cybersecurity researchers detected counterfeit pirated copies spreading the Lumma Stealer malware. This development raises significant concerns in the cybersecurity realm, as it provides cybercriminals with the means to access thousands of users’ laptops. Many illegal sites host files masquerading as legitimate video downloads of the film.
In numerous instances, these files are actually concealed versions of the Lumma Stealer malware, which infects viewers’ devices upon opening. Developed in Russia, Lumma Stealer is believed to be capable of stealing sensitive information, including saved accounts and payment details, session cookies, browsing history, remote access tools, messaging applications, and any other documents and files stored locally on the device.
With access to such a broad spectrum of data and tools, attackers can effectively seize not only the user’s device but also their financial resources and extensive network of contacts.
Pirated Movie Copies Used for Hacking Attacks
While the latest campaign involving “Odyssey” appears alarming, it continues a longstanding trend where popular films are utilized to disseminate hacking tools and malware. Cybercriminals typically exploit the window between a film’s theatrical release and its availability on legal streaming platforms like Netflix and Amazon Prime.
Bitdefender has identified several bait file names circulating online, including:
- the odyssey 2160phd (2026) engsubs eztv.exe
- the odyssey 2026 1080p h264-djt.exe
- the odyssey 2026 1080p webrip-lama.exe
Despite the promise of downloading the film, these are actually executable files for Windows, designed not for video playback but for infecting the victim’s device. Bitdefender cautioned that this list is far from exhaustive, and criminals are likely employing many other file names.
This tactic is not new. In 2025, researchers documented a nearly identical campaign involving fake downloads of “Mission: Impossible – The Last Calculation,” where attackers spread Lumma Stealer through torrent sites, disguising files as film releases. “The latest campaign simply substitutes one blockbuster for another. Instead of devising new attacks, criminals repeatedly use tried-and-true delivery methods, linking them to films currently dominating search engines and torrent sites,” the report states.
Torrent trackers are inundated with such malicious software. Popular films are not the only targets for Lumma and other stealers; TV series, pirated games, and software are also at risk. The situation is exacerbated by the fact that users on these sites often pay less attention to file types and names, as they are already aware that the content is illegal and are willing to overlook unusual file names.
To protect against such threats, Bitdefender emphasized the importance of watching films only through verified and legal streaming services, as well as the necessity of regularly updating cybersecurity software and operating systems.