logo

Gaming Engines: An Undetected Playground for Malware Loaders

ID: 69418452-5794-5f7b-ac85-fe326c9959c1

STIX ID: report--69418452-5794-5f7b-ac85-fe326c9959c1

Feed Name: Check Point Research

Threat Score
80/100

Date Published: 2024-11-27

Date Updated: 2026-04-27

Author: [email protected]

...
...

Check Point Research discovered GodLoader, a cross-platform loader that leverages Godot Engine .pck files and malicious GDScript to download and execute payloads (including XMRig and RedLine), distributed via a GitHub-based Stargazers Ghost Network DaaS since at least 2024-06-29; the technique employs sandbox-evasion, Defender-exclusion attempts, and remained largely undetected by AV while infecting an estimated 17,000+ machines—this report includes technical analysis, campaign timelines, IoCs, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.