Security firm Bitdefender has reported that shortly after the movie "Odyssey" was released, malicious files disguised as high-definition movie sources appeared online. These files appear to be common pirated video resources but are actually Windows executable programs that install data-stealing malware upon execution.
Disguised as source files for distribution
The report states that relevant files are often named as WEBRip or Blu-ray versions and accompanied by icons resembling VLC player or video files to reduce user vigilance. Since Windows hides file extensions by default, many users find it difficult to directly distinguish between ".exe" files and genuine video files.
Can steal wallet and account data
Once activated, Lumma Stealer collects browser-stored passwords, payment details, autofill information, remote desktop credentials, and cryptocurrency wallet data. Bitdefender also states that this malware steals authentication cookies, allowing attackers to hijack user sessions.
This means that even if users have enabled multi-factor authentication, some accounts may still be compromised due to session hijacking. The risk is not limited to wallet assets but may also affect email accounts, trading platforms, and other online services.
Popular content as common advertising entry points
Bitdefender believes this incident follows a common pattern seen in recent years: attackers hide malware within content that users are eager to download, spreading it through high-demand resources such as movies, game mods, wallpapers, or software packages.
The agency recommends that users watch films primarily through legitimate streaming services, avoid running executable files labeled as video content, and enable Windows file extension display to identify disguised files.
