logo

Surge in AI-Driven Phishing Attacks and QR Code Quishing in 2025 Spam and Phishing Report

ID: 16d21fa8-b057-59b9-88dd-1c2deb267b88

STIX ID: report--16d21fa8-b057-59b9-88dd-1c2deb267b88

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-13

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

RenEngine is an active campaign that distributes Lumma and ACR stealers by embedding a multi-stage loader into modified Ren'Py-based game launchers and cracked software. The loader performs sandbox detection, decrypts staged payloads, and uses DLL hijacking (dbghelp.dll) to inject final payloads into trusted processes (e.g., explorer.exe), enabling persistent in-memory theft of passwords, cookies, and cryptocurrency wallets; incidents have been observed in multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.