Secretus logo

The Odyssey Download Is an .exe — and Windows Hides That From You

·10 min read

Bitdefender is warning that fake pirated copies of The Odyssey are delivering Lumma Stealer. Christopher Nolan's film is in cinemas, IMAX screenings are sold out weeks ahead, and it is not on any streaming service yet. That gap — between everyone wanting to see something and nobody being able to watch it at home — is the entire business model.

The three filenames Bitdefender observed are worth reading carefully, because they contain the whole attack:

  • the odyssey 2160phd (2026) engsubs eztv.exe
  • the odyssey 2026 1080p h264-djt.exe
  • the odyssey 2026 1080p webrip-lama.exe

The filename is the attack

Two things are happening in those strings, and neither is technical sophistication.

First, the extension. A video file is not an executable. Nothing that plays a film ends in .exe. But Windows hides known file extensions by default, and has for decades, so in Explorer that first file displays as the odyssey 2160phd (2026) engsubs eztv — with a generic icon, in a folder of things you downloaded on purpose. The single most load-bearing part of this campaign is a display setting.

Second, the vocabulary. 2160p, h264, webrip, engsubs, and the trailing group tags — eztv, djt, lama — are real release-scene conventions. Someone who downloads films regularly reads those as provenance. They are the equivalent of a familiar logo: not proof of anything, but enough to stop you looking closer.

So the target is not the naive user. It is the experienced one, whose pattern recognition is being used against them. That is a more uncomfortable observation than “don't click strange files”, and a more accurate one.

What Lumma actually takes

Lumma Stealer is an infostealer sold as a service. Per Bitdefender it goes after saved logins and payment credentials, session cookies, browsing history, remote access tools and communication apps.

Read that list again and notice which item is the dangerous one. It is not the passwords.

Session cookies are post-authentication. A stolen cookie is a browser that has already logged in, already passed multi-factor authentication, already satisfied every check you configured. Replaying it does not require your password and does not trigger your authenticator. All the effort spent turning on MFA is bypassed, not defeated — the attacker simply arrives after the door.

This is also why “I changed my password” is an incomplete response. Changing a password does not, on most services, invalidate existing sessions. You have to revoke the sessions explicitly, and most people never find that setting.

The second-order effect is the one the industry cares about: stolen credentials do not stay with whoever stole them. They are sorted, packaged and sold, and the initial-access market is where ransomware crews shop. A home machine compromised by a fake film download is how a corporate VPN credential enters circulation.

Why this particular malware, and why now

Lumma is not new, and its recent history is instructive about how little takedowns achieve on their own.

In May 2025 a coalition led by Microsoft's Digital Crimes Unit with the FBI and Europol dismantled its infrastructure — roughly 2,300 domains seized, five core administration domains taken offline — after it had compromised more than 394,000 Windows machines in three months. It was a genuine, well-executed operation.

Targeted accounts began climbing again within about two months. By early 2026 the command infrastructure had been rebuilt, and Bitdefender reported activity concentrated in India with secondary volume across the US and Europe. Delivery evolved rather than stopped: GitHub abuse, loader frameworks that run payloads in memory, and fake CAPTCHA pages — the ClickFix technique we wrote about earlier this year, where the victim is talked into pasting a command themselves.

The pattern to take from that: seizing infrastructure removes capability for weeks, not years, when the operators are a business with customers. What persists is the demand side — and a film everyone wants to see is demand you cannot take down.

The same crew ran this play against Mission: Impossible in 2025. It is a seasonal business, and the season is whenever something big is in cinemas and not yet streaming.

If you are going to look for a copy anyway

Telling people not to pirate films is not advice, it is a position, and it does not change behaviour. So here is the practical version.

  1. Turn file extensions on. Do it now, before you need it. In Windows Explorer: View → Show → File name extensions. This single change makes the entire campaign visible, because a video that ends in .exe announces itself.
  2. Know what a video file can end in. .mkv, .mp4, .avi. Not .exe, not .scr, not .bat, not .lnk, and not a .zip whose only content is one of those.
  3. Be suspicious of size, not just name. A 2160p feature film is tens of gigabytes. A few hundred megabytes claiming to be one is not a good rip; it is not a film.
  4. Do not turn off your antivirus because a “guide” says to. Instructions to disable protection or add an exclusion before running something are not a workaround for false positives. They are step one of the attack, and they are in nearly every one of these packages.
  5. If you must, use a machine that does not matter. A separate account, a virtual machine, anything without your browser profile in it. The value being stolen is your saved sessions, so the defence is not having them present.

If you already ran one

This is the part most coverage skips, and it is the part that matters if you are reading this too late. Order matters here.

  1. Use a different device for everything below. Recovering an account from the compromised machine hands the new credentials straight back.
  2. Revoke sessions before changing passwords. On each important account — email first, then anything that can reset other accounts — find “sign out of all devices” or the active-sessions list and clear it. A password change alone often leaves the attacker's stolen cookie working.
  3. Then change passwords, starting with the email account that everything else resets through.
  4. Check what has been added, not just what has changed. Mail forwarding rules, filters that auto-archive security alerts, recovery addresses and phone numbers, OAuth apps with access to your account, and new authenticator enrolments. Persistence lives in configuration, and it survives a password reset untouched.
  5. Assume the browser vault is gone. Everything the browser had saved should be treated as disclosed, including things you forgot were in there.
  6. Rebuild rather than clean, if you can. An infostealer that ran with your privileges may have dropped more than itself, and “the scan came back clean” is a weaker statement than people take it for.

The part where we are honest about our own product

We build an encrypted secret-sharing tool, so there is an obvious temptation to end this by suggesting we would have helped. We would not have, and it is worth saying why plainly.

Every design decision we make assumes the two endpoints are trustworthy. Encryption in the browser, keys that never reach our servers, one-time links — all of it protects the secret in transit and at rest, and none of it protects a machine whose keyboard, clipboard and browser storage belong to someone else. If Lumma is running when you open a secret, it sees what you see.

The same applies to password managers, to MFA, to any tool in this category. They raise the cost of attacking you remotely. They do not survive the endpoint falling, and the honest version of “defence in depth” includes admitting which layer is load-bearing. Here, it is the machine.

Which is why the most valuable line in the whole Bitdefender advisory is also the least interesting one: watch it through a service that is meant to show it to you, and keep the machine you do that on patched.

Sources

Share a secret the safe way

Start a 14-day trial to send; recipients open one-time links without an account.

Try Secretus