Christopher Nolan's The Odyssey is one of the year's biggest film releases, and criminals wasted no time cashing in. Within hours of the movie reaching screens, researchers at Malwarebytes found scams built to trap people hunting for pirated copies, using fake browser warnings and malware dressed up as movie downloads.
The Malwarebytes Threat Intelligence team documented two main tricks. Neither relies on a software flaw. Both simply bank on a hugely popular title guaranteeing search traffic, the same social-engineering economics behind a steady run of fake-download campaigns IntelFusions has covered, from bogus game downloads that hide an infostealer to fake "fix your browser" prompts that steal saved logins.
The fake browser warning
On cloned torrent sites listing The Odyssey, visitors hit a pop-up reading "Browser Issue Detected," claiming a missing component is blocking access and pushing a prominent "Fix It Now" button. There is no missing component: the entire warning is just part of the web page, dressed up to look like a real browser alert. Clicking it funnels the user through a chain of advertising redirects that can end at a rogue browser extension, scareware pushing a fake tech-support phone number, or an outright malware download. Because the ad network swaps out what it serves over time, the final destination changes from visit to visit.
The movie that was actually a program
The second scam targets people who try to grab the film itself. Malwarebytes found a listing named "The Odyssey 2026 1080p WEBRip-LAMA.exe," advertised with hundreds of seeders to look popular and trustworthy. The ".exe" ending is the giveaway: that is a Windows application, not a video. Legitimate movies come as video files such as .mkv, .mp4, or .avi and open in a media player. This fake even wore VLC Media Player's familiar orange traffic-cone icon to seem harmless. Running it could drop whatever the operators choose that day, from a backdoor or an infostealer that lifts saved passwords and browser sessions to a loader or even ransomware.
What you should do
The simplest defense is a rule of thumb: a movie file that ends in .exe is never a movie, no matter how many seeders it shows. If you clicked "Fix It Now" and something downloaded or opened afterward, run a full malware scan and check your browser for extensions you do not recognize. If you ran a supposed movie that turned out to be a program, disconnect the device from the network, scan it, and change the passwords for important accounts from a separate, trusted machine before using it for anything sensitive.
The findings were published by the Malwarebytes Threat Intelligence team in their original report.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.