# Odyssey Piracy Scam Campaign: Malvertising and Icon-Spoofed Executables Targeting Movie Downloaders

> Within hours of the theatrical release of Christopher Nolan's 'The Odyssey', Malwarebytes identified a coordinated scam campaign using cloned torrent/piracy sites to serve a fake 'Browser Issue Detected' malvertising pop-up and a VLC-icon-spoofed executable ('The Odyssey 2026 1080p WEBRip-LAMA.exe') disguised with unrelated file metadata to trick pirates into running malware.

- **Published:** 2026-07-20T00:00:00Z
- **Last reviewed:** 2026-07-20T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1560
- **ID:** TL-2026-1560
- **Severity:** MEDIUM
- **Category:** SCAM
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 21 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Malwarebytes Threat Intelligence observed a scam campaign that emerged within hours of the July 2026 theatrical release of 'The Odyssey', directed by Christopher Nolan. The operation runs on cloned piracy/torrent sites that faithfully reproduce real listing layouts, cover artwork, and cast information from legitimate torrent trackers, indicating a template-driven, repeatable operation rather than a one-off page.

The campaign uses two parallel monetization/infection tracks. The first is a browser-based social-engineering track: visitors browsing cloned listing pages are shown an in-page overlay styled as a native browser warning, reading 'Browser Issue Detected' and claiming a required 'component' is missing. The overlay presents a prominent 'Fix It Now' call-to-action against a minimized 'Close and Continue Browsing' option, nudging victims toward the malicious path. Clicking 'Fix It Now' does not resolve any real issue; it routes the victim into a malvertising ad-network redirect chain that Malwarebytes assesses leads to rogue browser extension installs and/or fake technical-support-scam (TSS) call-center lures. The identical overlay, with only branding colors changed, was observed reused across multiple cloned torrent domains, confirming a shared campaign kit rather than independent copycats.

The second track targets users who attempt to actually download 'the movie'. A torrent-style listing named 'The Odyssey 2026 1080p WEBRip-LAMA' — presented with fabricated seeder/leecher counts (597 seeders, 520 leechers) to appear popular and trustworthy — resolves to a Windows PE executable rather than a genuine .mkv/.mp4/.avi video container. The dropped file, 'The Odyssey 2026 1080p WEBRip-LAMA.exe', is disguised using VLC Media Player's recognizable orange traffic-cone icon (T1036.005 icon spoofing) to exploit victim familiarity with the legitimate media player and suppress suspicion at the point of execution. Inspecting the executable's file description metadata reveals unrelated text ('wireless bus Business Controller'), which Malwarebytes assesses is leftover build metadata from whatever legitimate software project the malware author's build toolchain or packer was originally derived from or repurposed atop — a further indicator of inauthenticity that a careful user could catch before execution.

Malwarebytes did not publicly disclose a specific malware family classification, C2 infrastructure, or file hash for the payload at time of reporting, but assessed that the intended terminal payload profile for icon-spoofed 'movie' executables of this kind commonly includes trojans that open a backdoor into the system, infostealers that harvest saved browser passwords and active browser sessions, generic loaders staged to fetch additional malware, and in more severe cases ransomware.

This campaign fits a broader, currently active piracy-malware trend Malwarebytes has tracked through 2026: a companion campaign reported the prior month used cracked/repacked PC game installers (bait titles included Far Cry, Need for Speed, FIFA, and Assassin's Creed) that abused a legitimate Ren'Py visual novel engine launcher to quietly kick off an infection chain, delivering the ARC infostealer, Rhadamanthys stealer, an Async RAT, and Backdoor.XWorm to over 400,000 infected devices globally (~30,000 in the US). While a different bait category (games vs. film) and technical delivery mechanism (RenEngine abuse vs. icon-spoofed standalone .exe), both campaigns share the same underlying tradecraft: exploit high-demand piracy searches around a topical release, disguise a Windows executable as legitimate creative-media software, and rely on victim urgency/excitement to bypass normal security scrutiny.

Remediation guidance from Malwarebytes: users who clicked 'Fix It Now' on the fake browser-warning overlay should run a full malware scan and audit installed browser extensions for anything unrecognized. Users who executed the spoofed .exe should immediately disconnect the affected machine from the network, run a full malware scan, avoid using the device for banking/email/other sensitive activity until cleared, and change passwords for important accounts from a separate, known-clean device.

## MITRE ATT&CK

- T1583.001 Domains
- T1585.001 Social Media Accounts
- T1566.002 Spearphishing Link
- T1189 Drive-by Compromise
- T1204.002 Malicious File
- T1036.005 Match Legitimate Resource Name or Location
- T1036.003 Rename Legitimate Utilities
- T1218 System Binary Proxy Execution
- T1027 Obfuscated Files or Information
- T1555.003 Credentials from Web Browsers
- T1560 Archive Collected Data
- T1105 Ingress Tool Transfer
- T1486 Data Encrypted for Impact
- T1608 Stage Capabilities
- T1204.001 Malicious Link
- T1027.002 Software Packing
- T1140 Deobfuscate/Decode Files or Information
- T1497 Virtualization/Sandbox Evasion
- T1552.001 Credentials In Files
- T1082 System Information Discovery
- T1057 Process Discovery
- T1005 Data from Local System
- T1547.001 Registry Run Keys / Startup Folder
- T1071.001 Web Protocols
- T1219 Remote Access Tools

## Sources

- [The Odyssey piracy scams appear within hours of the movie's release](https://www.malwarebytes.com/blog/threat-intel/2026/07/the-odyssey-piracy-scams-appear-within-hours-of-the-movies-release)
- [Pirated PC games are delivering password-stealing malware](https://www.malwarebytes.com/blog/threat-intel/2026/06/pirated-pc-games-are-delivering-password-stealing-malware)
- [Yet another case of malvertising on The Pirate Bay](https://www.malwarebytes.com/blog/news/2014/09/malvertising-on-the-pirate-bay)
- [Malwarebytes Threat Alert | OSX.Odyssey](https://www.malwarebytes.com/blog/detections/osx-odyssey)
- [MacOS malware Poseidon Stealer rebranded as Odyssey Stealer](https://www.scworld.com/news/macos-malware-poseidon-stealer-rebranded-as-odyssey-stealer)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1560
