logo

The game is over: when “free” comes at too high a price. What we know about RenEngine

ID: 2d91adbe-9d26-5ed3-93c6-bfa61637c8da

STIX ID: report--2d91adbe-9d26-5ed3-93c6-bfa61637c8da

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-29

Author: Denis Brylev, Pavel Sinenko, Maxim Starodubov, Artem Ushkov

...
...

This Kaspersky analysis details a widespread campaign (since March 2025) that distributes a RenEngine loader packaged as pirated games and cracked software; the loader uses a modular HijackLoader deployment that performs in-memory DLL overwrites, transaction-based temporary file staging, and process injection to deliver infostealers (Lumma, ACR, with instances of Vidar), provides IOCs (file hashes and malicious domains), and offers mitigation advice such as installing software from trusted sources and using behavior-based security solutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.