logo

Hackers abuse popular Godot game engine to infect thousands of PCs

ID: 81e01257-64c8-5956-b541-d44454bc2ec2

STIX ID: report--81e01257-64c8-5956-b541-d44454bc2ec2

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-11-27

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

Check Point Research uncovered a GodLoader malware campaign that abuses the Godot game engine and GDScript to embed and execute malicious code inside .pck game package files, evading many antivirus detections and enabling credential theft and additional payload delivery (including XMRig). The attackers used the Stargazers Ghost Network DaaS and hundreds of GitHub ghost repositories to distribute infected tools and games across multiple waves (Sept–Oct 2024), with researchers estimating over 17,000 infected systems and showing the technique can be adapted to Windows, macOS, Linux, Android, and iOS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.