The game is over: when “free” comes at too high a price. What we know about RenEngine
ID: 2d91adbe-9d26-5ed3-93c6-bfa61637c8da
STIX ID: report--2d91adbe-9d26-5ed3-93c6-bfa61637c8da
Feed Name: Securelist by Kaspersky
Date Published: 2026-02-11
Date Updated: 2026-04-29
Author: Denis Brylev, Pavel Sinenko, Maxim Starodubov, Artem Ushkov
This Kaspersky analysis details a widespread campaign (since March 2025) that distributes a RenEngine loader packaged as pirated games and cracked software; the loader uses a modular HijackLoader deployment that performs in-memory DLL overwrites, transaction-based temporary file staging, and process injection to deliver infostealers (Lumma, ACR, with instances of Vidar), provides IOCs (file hashes and malicious domains), and offers mitigation advice such as installing software from trusted sources and using behavior-based security solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
