RenEngine Loader Deploys Stealthy Multi-Stage Execution to Bypass Security Measures
ID: 6f765909-81fb-5601-83e2-371b3e9fc2b9
STIX ID: report--6f765909-81fb-5601-83e2-371b3e9fc2b9
Feed Name: GBHackers
**Executive summary:** A large-scale, ongoing stealer campaign (active since April 2025) abuses Ren'Py game launcher archives distributed via pirated game downloads to deploy a multi-stage loader (RenEngine → evolved HijackLoader) that uses sandbox/VM checks, DLL side‑loading, module stomping, and process doppelgänging to install information stealers (notably ACR Stealer), reportedly compromising ~400,000 victims with ≈5,000 new infections per day and exfiltrating browser credentials, cookies, crypto wallet data, system information, and clipboard contents.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
