Malware disguised as pirated 'Odyssey' movie files steals crypto wallet data

icon币界网
Share
AI summary iconSummary
Malicious files disguised as pirated downloads of the movie "Odyssey" are spreading the Lumma Stealer malware, targeting cryptocurrency wallet data. These files, often labeled as WEBRip or Blu-ray, install data-stealing software that harvests browser passwords, payment information, and crypto credentials. Bitdefender warns that session cookies can be hijacked, even when multi-factor authentication is enabled. As cryptocurrency news highlights rising threats, users are urged to avoid suspicious downloads. Inflation data may not be the only risk—malware is now a key concern for traders.
CoinDesk reports:

Security firm Bitdefender has reported that shortly after the movie "Odyssey" was released, malicious files disguised as high-definition movie sources appeared online. These files appear to be common pirated video resources but are actually Windows executable programs that install data-stealing malware upon execution.

Disguised as source files for distribution

The report states that relevant files are often named as WEBRip or Blu-ray versions and accompanied by icons resembling VLC player or video files to reduce user vigilance. Since Windows hides file extensions by default, many users find it difficult to directly distinguish between ".exe" files and genuine video files.

Can steal wallet and account data

Once activated, Lumma Stealer collects browser-stored passwords, payment details, autofill information, remote desktop credentials, and cryptocurrency wallet data. Bitdefender also states that this malware steals authentication cookies, allowing attackers to hijack user sessions.

This means that even if users have enabled multi-factor authentication, some accounts may still be compromised due to session hijacking. The risk is not limited to wallet assets but may also affect email accounts, trading platforms, and other online services.

Popular content as common advertising entry points

Bitdefender believes this incident follows a common pattern seen in recent years: attackers hide malware within content that users are eager to download, spreading it through high-demand resources such as movies, game mods, wallpapers, or software packages.

The agency recommends that users watch films primarily through legitimate streaming services, avoid running executable files labeled as video content, and enable Windows file extension display to identify disguised files.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.