logo

RenEngine Loader Using Stealthy Multi‑Stage Execution Chain to Bypass Security Controls

ID: 61a715a7-f71f-58a7-b4f2-63d56ef7ba4d

STIX ID: report--61a715a7-f71f-58a7-b4f2-63d56ef7ba4d

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-06

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Cracked game installers are being abused to deliver a dual‑loader malware chain: RenEngine (a Ren'Py‑based loader) that decrypts and launches a second stage, and HijackLoader which uses DLL side‑loading and module stomping to deploy infostealers (ACR Stealer and sometimes Vidar). The campaign, active since at least April 2025, is widespread (estimated ~400,000 victims, ~5,000 new hits/day) and uses Base64/XOR staging plus VM/GPU anti‑analysis checks to evade detection; defenders should treat pirated installers and mods as high risk and monitor for Ren'Py RPA unpacking, DLL side‑loading, and sudden credential/crypto theft traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.