logo

RenEngine Loader Deploys Stealthy Multi-Stage Execution to Bypass Security Measures

ID: 6f765909-81fb-5601-83e2-371b3e9fc2b9

STIX ID: report--6f765909-81fb-5601-83e2-371b3e9fc2b9

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-02-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive summary:** A large-scale, ongoing stealer campaign (active since April 2025) abuses Ren'Py game launcher archives distributed via pirated game downloads to deploy a multi-stage loader (RenEngine → evolved HijackLoader) that uses sandbox/VM checks, DLL side‑loading, module stomping, and process doppelgänging to install information stealers (notably ACR Stealer), reportedly compromising ~400,000 victims with ≈5,000 new infections per day and exfiltrating browser credentials, cookies, crypto wallet data, system information, and clipboard contents.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.