Pirated PC games are delivering password-stealing malware
ID: 5468f9fd-fa15-51b4-9efd-77d9b5c26433
STIX ID: report--5468f9fd-fa15-51b4-9efd-77d9b5c26433
Feed Name: Security Boulevard
Researchers have identified a Windows malware campaign that hides a loader called “RenEngine loader” inside cracked or repacked PC game installers by abusing a Ren'Py launcher. The loader drops infostealers (ARC, Rhadamanthys) and other payloads (Async RAT, Backdoor.XWorm), enabling credential and crypto theft as well as remote access; researchers estimate more than 400,000 devices infected worldwide. The report advises avoiding pirated software, using up-to-date anti-malware, and following cleanup guidance if infected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
