logo

Pirated PC games are delivering password-stealing malware

ID: 5468f9fd-fa15-51b4-9efd-77d9b5c26433

STIX ID: report--5468f9fd-fa15-51b4-9efd-77d9b5c26433

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Malwarebytes

...
...

Researchers have identified a Windows malware campaign that hides a loader called “RenEngine loader” inside cracked or repacked PC game installers by abusing a Ren'Py launcher. The loader drops infostealers (ARC, Rhadamanthys) and other payloads (Async RAT, Backdoor.XWorm), enabling credential and crypto theft as well as remote access; researchers estimate more than 400,000 devices infected worldwide. The report advises avoiding pirated software, using up-to-date anti-malware, and following cleanup guidance if infected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.