Kaspersky researchers detail RenEngine, a malware loader distributed since March 2025 through pirated games and software. The loader uses modified Ren'Py game launchers to deploy HijackLoader, which then delivers info-stealing malware like Lumma and ACR Stealer. The attack chain involves sophisticated techniques including

7m read timeFrom securelist.com
Post cover image
Table of contents
Incident analysisNot only gamesDistributionRecommendations for protectionIndicators of compromise

Sort: