Gaming Engines: An Undetected Playground for Malware Loaders
ID: 69418452-5794-5f7b-ac85-fe326c9959c1
STIX ID: report--69418452-5794-5f7b-ac85-fe326c9959c1
Feed Name: Check Point Research
Check Point Research discovered GodLoader, a cross-platform loader that leverages Godot Engine .pck files and malicious GDScript to download and execute payloads (including XMRig and RedLine), distributed via a GitHub-based Stargazers Ghost Network DaaS since at least 2024-06-29; the technique employs sandbox-evasion, Defender-exclusion attempts, and remained largely undetected by AV while infecting an estimated 17,000+ machines—this report includes technical analysis, campaign timelines, IoCs, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
