Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Fake movie downloads spread Lumma Stealer malware

Threat actors are distributing the Lumma Stealer malware via fake pirated movie downloads, specifically exploiting the release of "The Odyssey" by disguising malicious .exe files with VLC icons. The attack leverages the default Windows setting of hiding file extensions to trick users into executing the malware, which harvests credentials, session cookies, and financial data. The campaign focuses on immediate credential theft, with stolen session cookies posing a significant risk as they can bypass multi-factor authentication.
Read Full Article →

Malware Fake movie downloads spread Lumma Stealer malware August 12, 2026 Share By SC Staff (Adobe Stock) As noted by Tech Radar, attackers are leveraging the release of the film "The Odyssey" to distribute the Lumma Stealer malware. Threat actors are disguising malicious executable files as pirated copies of the movie, aiming to trick users into downloading and running them. Bitdefender has identified that fake downloads of "The Odyssey," presented as scene releases with .exe files disguised by VLC icons, are actively spreading Lumma Stealer. This malware, a prominent information stealer sold as a malware-as-a-service, harvests sensitive data including browser passwords, session cookies, payment information, and cryptocurrency wallet details. The attackers exploit the default Windows setting that hides file extensions, making the malicious .exe files appear as legitimate video files to unsuspecting users. These malicious builds are noted to be less sophisticated in terms of persistence mechanisms compared to previous campaigns, focusing instead on immediate credential theft. The danger lies in stolen session cookies, which allow attackers to bypass multi-factor authentication and maintain access to compromised accounts. This tactic is not new, as similar campaigns have been documented using other popular movie releases. Source: Tech Radar SC Staff Related Malware 77 malicious extensions found on Open VSX marketplace SC Staff August 5, 2026 Seventy-seven malicious extensions impersonating legitimate developer tools were discovered on the Open VSX marketplace, transmitting system and development environment information. Malware AI-driven cybercrime surges in Africa, accounting for 55% of reported digital crime SC Staff August 5, 2026 AI-driven cybercrime now constitutes 55% of all reported digital crime in Africa, according to a new report from Interpol. Malware New npm packages deliver remote access trojan targeting Alibaba developers SC Staff August 4, 2026 A new set of malicious npm packages were discovered targeting users of Alibaba developer tools with a cross-platform remote access trojan (RAT). Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article