Movie buffs are risking more than just disappointing themselves – and Matt Damon –by downloading pirated copies of Christopher Nolan’s take on The Odyssey, according to security researchers.
The immensely popular film has already raked in more than US$1 billion at the box office, and it’s proving just as popular for torrenting fans.
However, movie lovers wanting to see Matt Damon find his own way home for once may end up with more than they bargained for, as cyber criminals are seeding the Lumma Stealer malware disguised as the film across the internet to steal personal data from the unwary.
According to cyber security firm Bitdefender, the files may look convincing, with file names such as "the odyssey 2026 1080p webrip”, complete with icons that even look like VLC files, but the files are in fact malicious info-stealer programs.
Since Windows hides file names by default, film fans may think they’re about to open the film; instead setting themselves up to have their passwords, payment information, login sessions, and even crypto wallet details scraped and stolen.
“Malware weaved into pirated or cracked content is not all that new, but until a couple of years ago it was mostly found in software or games,” Silviu Stahie, Security Analyst at Bitdefender, told Cyber Daily.
“This type of content, cracked games and apps, still carries a very high risk of infection. This hasn’t changed, especially since it’s easy to disguise a .exe file when the user expects to see it.”
Stahie said that cybercriminals have long known that popular films were a prime target for such campaigns. In 2025, the Tom Cruise hit Mission: Impossible – The Final Reckoning received similar attention from criminals.
Popular television shows, with weekly schedules, are also a target, thanks to the regularity of searches for pirated versions.
In addition, the data gained through such campaigns is highly valuable, as it can often be used for further compromise.
“For example, if the user saves login cookies (from websites that have the option to remember you for the next visit so you don’t have to enter credentials again), it becomes trivial for criminals to directly access online accounts without even triggering multi-factor authentication solutions,” Stahie said.
“Stolen passwords and other sensitive information will end up on the dark net, for sale. The motivation is purely financial, and this simple act of trying to watch a pirated movie will likely feed numerous cogs in an ever-expanding criminal industry.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.