Threat reportScamTL-2026-1560
Odyssey Piracy Scam Campaign: Malvertising and Icon-Spoofed Executables Targeting Movie Downloaders
Odyssey Piracy Scam Campaign (TL-2026-1560), also tracked as The Odyssey piracy scam, is a medium-severity scam threat, first published 2026-07-20. It has no confirmed attribution, affects Microsoft Windows (end-user desktop OS), maps to 25 MITRE ATT&CK techniques (T1005, T1027, T1027.002), and is covered by 9 detection rules and 21 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 25MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 21Indicators of compromise
Key facts for TL-2026-1560
- Threat ID
- TL-2026-1560
- Also known as
- The Odyssey piracy scam, Odyssey WEBRip-LAMA scam
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- SCAM
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- consumer, mediaentertainmentconsumers, generalpublic
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 21
Malware and tooling in Odyssey Piracy Scam Campaign
Malware and tooling: ARC_infostealer, AsyncRAT, Backdoor.XWorm, Rhadamanthys_stealer, RenEngine_loader, malvertising_ad_network_redirect_chain
How Odyssey Piracy Scam Campaign works
Within hours of the theatrical release of Christopher Nolan's 'The Odyssey', Malwarebytes identified a coordinated scam campaign using cloned torrent/piracy sites to serve a fake 'Browser Issue Detected' malvertising pop-up and a VLC-icon-spoofed executable ('The Odyssey 2026 1080p WEBRip-LAMA.exe') disguised with unrelated file metadata to trick pirates into running malware.
Malwarebytes Threat Intelligence observed a scam campaign that emerged within hours of the July 2026 theatrical release of 'The Odyssey', directed by Christopher Nolan. The operation runs on cloned piracy/torrent sites that faithfully reproduce real listing layouts, cover artwork, and cast information from legitimate torrent trackers, indicating a template-driven, repeatable operation rather than a one-off page.
The campaign uses two parallel monetization/infection tracks. The first is a browser-based social-engineering track: visitors browsing cloned listing pages are shown an in-page overlay styled as a native browser warning, reading 'Browser Issue Detected' and claiming a required 'component' is missing. The overlay presents a prominent 'Fix It Now' call-to-action against a minimized 'Close and Continue Browsing' option, nudging victims toward the malicious path. Clicking 'Fix It Now' does not resolve any real issue; it routes the victim into a malvertising ad-network redirect chain that Malwarebytes assesses leads to rogue browser extension installs and/or fake technical-support-scam (TSS) call-center lures. The identical overlay, with only branding colors changed, was observed reused across multiple cloned torrent domains, confirming a shared campaign kit rather than independent copycats.
The second track targets users who attempt to actually download 'the movie'. A torrent-style listing named 'The Odyssey 2026 1080p WEBRip-LAMA' — presented with fabricated seeder/leecher counts (597 seeders, 520 leechers) to appear popular and trustworthy — resolves to a Windows PE executable rather than a genuine .mkv/.mp4/.avi video container. The dropped file, 'The Odyssey 2026 1080p WEBRip-LAMA.exe', is disguised using VLC Media Player's recognizable orange traffic-cone icon (T1036.005 icon spoofing) to exploit victim familiarity with the legitimate media player and suppress suspicion at the point of execution. Inspecting the executable's file description metadata reveals unrelated text ('wireless bus Business Controller'), which Malwarebytes assesses is leftover build metadata from whatever legitimate software project the malware author's build toolchain or packer was originally derived from or repurposed atop — a further indicator of inauthenticity that a careful user could catch before execution.
Malwarebytes did not publicly disclose a specific malware family classification, C2 infrastructure, or file hash for the payload at time of reporting, but assessed that the intended terminal payload profile for icon-spoofed 'movie' executables of this kind commonly includes trojans that open a backdoor into the system, infostealers that harvest saved browser passwords and active browser sessions, generic loaders staged to fetch additional malware, and in more severe cases ransomware.
This campaign fits a broader, currently active piracy-malware trend Malwarebytes has tracked through 2026: a companion campaign reported the prior month used cracked/repacked PC game installers (bait titles included Far Cry, Need for Speed, FIFA, and Assassin's Creed) that abused a legitimate Ren'Py visual novel engine launcher to quietly kick off an infection chain, delivering the ARC infostealer, Rhadamanthys stealer, an Async RAT, and Backdoor.XWorm to over 400,000 infected devices globally (~30,000 in the US). While a different bait category (games vs. film) and technical delivery mechanism (RenEngine abuse vs. icon-spoofed standalone .exe), both campaigns share the same underlying tradecraft: exploit high-demand piracy searches around a topical release, disguise a Windows executable as legitimate creative-media software, and rely on victim urgency/excitement to bypass normal security scrutiny.
Remediation guidance from Malwarebytes: users who clicked 'Fix It Now' on the fake browser-warning overlay should run a full malware scan and audit installed browser extensions for anything unrecognized. Users who executed the spoofed .exe should immediately disconnect the affected machine from the network, run a full malware scan, avoid using the device for banking/email/other sensitive activity until cleared, and change passwords for important accounts from a separate, known-clean device.
MITRE ATT&CK techniques used in TL-2026-1560
Collection
T1005 Data from Local System; T1560 Archive Collected Data
Defense Evasion
T1027 Obfuscated Files or Information; T1027.002 Software Packing; T1036.003 Rename Legitimate Utilities; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion
Discovery
T1057 Process Discovery; T1082 System Information Discovery
Command and Control
T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1219 Remote Access Tools
Initial Access
T1189 Drive-by Compromise; T1566.002 Spearphishing Link
Execution
T1204.001 Malicious Link; T1204.002 Malicious File
Impact
T1486 Data Encrypted for Impact
Persistence
T1547.001 Registry Run Keys / Startup Folder
Credential Access
T1552.001 Credentials In Files; T1555.003 Credentials from Web Browsers
Resource Development
T1583.001 Domains; T1585.001 Social Media Accounts; T1608 Stage Capabilities
Affected products and versions in Odyssey Piracy Scam Campaign
- Microsoft — Windows (end-user desktop OS)
Vulnerable versions: All Windows versions capable of executing user-run .exe files
Remediation for Odyssey Piracy Scam Campaign
Immediate actions
- If 'Fix It Now' was clicked on a cloned-site browser warning, run a full Malwarebytes/antivirus scan immediately
- If the spoofed .exe was executed, disconnect the machine from the network immediately
- Do not use a potentially infected device for banking, email, or other sensitive-account access
- Audit installed browser extensions and remove anything not explicitly installed by the user
Workarounds
- Verify downloaded 'movie' files use genuine video containers (.mkv, .mp4, .avi) and refuse to run any .exe presented as a movie download
- Treat any in-page prompt to 'fix' the browser, install a component, or run software while browsing a piracy site as malicious
Longer-term hardening
- Change passwords for important accounts from a separate, known-clean device after cleanup
- Deploy web-filtering/DNS security to block known malvertising ad-network redirect chains
- User awareness training on icon-spoofed executables and fake 'Browser Issue Detected' overlays
- Block execution of unsigned/unknown .exe files downloaded via torrent/P2P clients through application allowlisting
Timeline of Odyssey Piracy Scam Campaign
- Malwarebytes' 2025 reporting on 'Odyssey Stealer' (a rebrand of the macOS Poseidon Stealer) is a distinct, unrelated macOS malware family that shares only the 'Odyssey' naming coincidence with this 2026 Windows piracy scam; noted to avoid cross-tracking confusion.
- Malwarebytes reports a related but distinct piracy-malware campaign abusing cracked PC game installers (Far Cry, Need for Speed, FIFA, Assassin's Creed) and the Ren'Py engine launcher to deliver ARC infostealer, Rhadamanthys, Async RAT, and Backdoor.XWorm to 400,000+ devices globally, establishing the broader 2026 piracy-malware trend this campaign belongs to.
- Malwarebytes assesses the malvertising redirect chain triggered by the 'Fix It Now' button terminates in rogue browser extension installs and/or fake technical-support-scam call-center lures.
- Malwarebytes publishes threat intelligence blog 'The Odyssey piracy scams appear within hours of the movie's release' documenting the campaign and issuing remediation guidance.
- Torrent listing 'The Odyssey 2026 1080p WEBRip-LAMA' identified resolving to a VLC-icon-spoofed Windows executable rather than a genuine video file.
- Fake 'Browser Issue Detected' overlay with malvertising redirect identified on multiple cloned torrent site clones, sharing an identical template with only branding colors changed.
- Malwarebytes observes cloned piracy/torrent sites and malicious executable listings appearing within hours of the film's release, indicating pre-staged infrastructure.
- 'The Odyssey', directed by Christopher Nolan, receives its theatrical release.
Sources cited for Odyssey Piracy Scam Campaign
Detection coverage for TL-2026-1560
As of 2026-07-20, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1560 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.