According to the security company Bitdefender, shortly after the movie Odyssey was released, researchers discovered a collection of Windows implementable documents disguised as pirated films. These documents look like a video resource, which, when actually operational, puts a malicious program into the computer, including the encrypted wallet, browser vouchers and payment information.
Dressed into video file dissemination
Bitdefender states that the file name is designed to be similar to a pirated film resource and that the attackers change the icon to a VLC player or a regular video file style to reduce user vigilance. Because Windows defaults to hide the known file extension, the user may only see the movie name and player icon, ignoring the actual.exe file.
Researchers point out that users who frequently visit a seed site may accept an abnormal file name, a compressed package or an attached player, which makes it easier for malicious documents to mix into the download process. Bitdefender states that its safety products have intercepted the identified samples, but this does not preclude the attackers from continuing to disseminate using other documentary names.
Lumma can steal wallets and sessions
Once the file is executed, Lumma Stealer will search for browser passwords, saved payment information, auto-filling records, remote desktop vouchers and encrypted wallet data. It also collects browser authentication for Cookie, which means that the attackers may take over the log-in accounts directly, even if multiple identifications are opened by the victim.
In its analysis of the sample, Bitdefender found an attempt to connect to the control infrastructure associated with Lumma Stealer and identified several associated domain names. It states that these addresses have been intercepted from its clients.
LummaC2 is known as an “information poacher or service” and according to Bitdefender and United States law enforcement, the malicious software was developed by Russian background developers and sold in the underground market. Buyers can also initiate data theft without having to prepare their own malicious codes.
US previously seized domain name
In May 2025, the United States Department of Justice applied for the seizure of 5 domain names used by LummaC2 administrators, and Microsoft initiated civil proceedings covering approximately 2300 associated domain names during the same period. Court documents show that the FBI identified at least 1.7 million cases in which LummaC2 was used to steal information, including browser records, mailboxes and bank log-in information, as well as notes with access to encrypted wallets.
The United States Department of Justice stated at that time that law enforcement had seized two domain names on 19 May 2025. The following day, the new addresses were quickly seized after LummaC2 administrators provided three alternative domain names to their clients.
A new discovery by Bitdefender in 2026 showed that the attacks around the Lumma family did not stop after law enforcement operations in 2025. The company did not disclose the number of victims of the “Odyssey” bait attack, the scale of the loss of encrypted assets or the regional distribution.
Knowledge is being used repeatedly as bait.
The report mentions that film piracy resources are only a shell for the recent dissemination of malicious software. Microsoft also disclosed earlier this month a fake CAPTCHA attack, in which the attackers, through the BNB Chain smart contract, issued orders and dropped a number of malicious programs, including Lumma Stealer.
In addition, the mobile end and developer tools serve as a gateway to wallet data. SparkKitty, previously exposed, collects pictures from mobile phone albums, and some users keep wallets, passwords, or 2-dimensional amplifiers in albums; Socket in May this year disclosed that TrapDoor's malicious packages had appeared in npm, PyPI and Rust warehouses, including encryption and AI developers.
