Originals

Lumma Stealer Malware Rides Back Into Crypto Wallets via Fake ‘Odyssey’ Downloads

Lumma Stealer Malware Rides Back Into Crypto Wallets via Fake ‘Odyssey’ Downloads

Fans hunting for a free copy of “The Odyssey” may be installing something other than a movie. Bitdefender says fake pirated downloads of the 2026 blockbuster are being used to spread Lumma Stealer, malware built to scrape cryptocurrency wallets, saved passwords and browser session data from infected Windows machines, according to reports from Decrypt and Crypto Briefing.

Both outlets, reporting on the same Bitdefender advisory, describe malicious files disguised as legitimate video downloads. Decrypt reported the files are disguised as high-definition WEBRip and Blu-ray-style rips with names mimicking legitimate torrent releases, while Crypto Briefing described them as high-resolution video downloads with filenames designed to mimic piracy-scene conventions and popular release-group naming formats. The .exe extension is the giveaway, Crypto Briefing noted, but attackers dress the icon to resemble VLC Media Player to reduce suspicion — a detail both outlets report. Decrypt added that the disguise works in part because Windows hides file extensions by default, leaving many users unable to distinguish an executable from an actual video file.

What Lumma Stealer does once it runs

According to Decrypt, once executed, Lumma Stealer scrapes browser passwords, saved payment details, autofill data, remote desktop credentials and crypto wallets from the infected machine. Crypto Briefing’s description overlaps closely, listing saved browser logins, autofill entries, card numbers stored in Chrome or Edge, and crypto wallet credentials among the data the malware pulls from a compromised device.

Both outlets flag the same specific danger for crypto holders: the malware also lifts authentication cookies. Decrypt reported this lets attackers hijack accounts even with multi-factor authentication switched on. Crypto Briefing framed the mechanism in more detail, reporting that a stolen session cookie lets an attacker replay a victim’s active browser session on an exchange or wallet interface without needing a password or an authenticator code at all.

Where the two accounts agree

On the core facts, Decrypt and Crypto Briefing line up closely. Both report that the malicious files are Windows executables masquerading as video files. Both report the VLC-icon disguise. Both describe the same data-theft capabilities — wallets, passwords, payment details, session cookies — and both frame the session-cookie theft as the feature that makes this campaign particularly dangerous for crypto users, since it can defeat multi-factor authentication protections that would otherwise stop a stolen password from being useful.

Where the accounts diverge

The two reports part ways on specifics neither one fully covers. Crypto Briefing named two command-and-control domains identified in Bitdefender’s analysis, auditva[.]cyou and logmabx[.]click, and reported that both were already flagged and blocked by Bitdefender’s security products at the time of the advisory. Decrypt reported only that Bitdefender’s products blocked the downloads and flagged command-and-control domains tied to the operation, without naming them.

Crypto Briefing also reported a separate, and larger, piece of history: a May 2025 law-enforcement operation that neutralized roughly 2,300 domains tied to Lumma Stealer’s infrastructure, after which the malware resurfaced and rebuilt its distribution channels. Decrypt’s account does not mention that takedown. Instead, Decrypt drew a different historical parallel, reporting that the current campaign mirrors a near-identical operation in 2025 that hid the same malware inside fake “Mission: Impossible – The Final Reckoning” files — a comparison Crypto Briefing’s account does not include.

The most concrete disagreement between the two reports is the timing of Bitdefender’s disclosure itself. Crypto Briefing stated plainly that Bitdefender disclosed the findings on August 6, 2026. Decrypt’s article, published the same day as Crypto Briefing’s, says only that Bitdefender made the announcement “this week” and embeds a Bitdefender social media post dated August 12, 2026. Neither outlet explains the gap, and nothing in either report reconciles a disclosure date nearly a week apart from the dated tweet Decrypt cites as its source. Readers should treat the exact disclosure date as unresolved.

A malware-as-a-service problem, not a one-off

Crypto Briefing reported that Lumma operates on a malware-as-a-service model, meaning its developers license the stealer to other criminals who pick their own distribution channels — cracked software, fake CAPTCHA pages and phishing emails among the previous vectors, per Crypto Briefing. That structure helps explain why a takedown of infrastructure doesn’t kill the underlying tool: per Crypto Briefing, take down one distributor’s domains and another campaign appears using fresh ones.

Decrypt situated the campaign within a broader pattern of wallet-draining malware riding in on content people want. The outlet cited, without independent verification here beyond its own reporting, prior schemes including malware delivered through fake CAPTCHA pages routed via BNB Chain, a mobile-app campaign called SparkKitty, malicious “anime girl” wallpapers aimed at Steam gamers, and a booby-trapped Python library used to poison developer tooling. The common thread Decrypt drew is that the malware rides in on something the victim actively wants — a pirated film, a game mod, or a coding package.

What’s not known

Neither outlet reports a confirmed victim count or a dollar figure for cryptocurrency stolen through this specific “Odyssey” campaign. Neither report links to or quotes Bitdefender’s full technical advisory, so the complete list of command-and-control domains and any sample file hashes have not been independently verified beyond these two secondary accounts. It also remains unclear, based on the available reporting, exactly which date should be treated as Bitdefender’s original disclosure.

What Bitdefender recommends

Per Decrypt, Bitdefender’s advice is direct: stick to legitimate streaming services, never run a file advertised as a video, and enable Windows’ file-extension display so a disguised executable can’t pass as a movie file.

Sources

Every fact above is attributed to one of these reports. Where they disagree, the article says so.