RenEngine Loader Uses Complex Chain To Bypass Security

RenEngine Loader Uses Complex Chain To Bypass Security
A sophisticated new malware campaign, RenEngine Loader, is affecting over 400,000 victims worldwide.

The attackers use a stealthy, multi-stage execution chain that is designed to evade detection by bypassing security controls and frustrating manual analysis.

By embedding a modular second-stage loader inside a legitimate application, the RenEngine Loader significantly mimics normal application behavior, making early detection much harder.

Operational Scale and Stealthy Execution

Since its initial emergence in April 2025, the RenEngine Loader campaign has continued to infect over 5,000 new victims daily.

The campaign blends social engineering techniques with technical evasion measures, enabling the malware to persist and scale efficiently.

Distribution of users reached C2 across the globe (Source: cyderes)
Distribution of users reached C2 across the globe (Source: Cyderes)

The attackers exploit a legitimate game launcher, Ren’Py, to deliver the malicious payload. By embedding their malicious scripts within Ren’Py archives, they hide the malware in plain sight, enabling it to behave like a normal application during execution.

Campaign Scale and Victim Impact

CountryUsers Reached
India38,016
United States31,317
Brazil25,220
Russian Federation22,366
Egypt19,500
Turkey18,835
Spain18,109
Indonesia15,790
Pakistan15,426
France14,100

The RenEngine Loader campaign starts with the distribution of cracked or modded game installers, often available on piracy platforms.

Daily user traffic from Oct. 14, 2025 to Jan. 5, 2026 by telemetry (Source: cyderes)
Daily user traffic from Oct. 14, 2025 to Jan. 5, 2026 by telemetry (Source: cyderes)

These files are advertised as pre-activated or cracked versions of popular games like Far Cry, Need for Speed, FIFA, and Assassin’s Creed. Users trust these files and execute them without further verification, unaware that they contain malicious payloads.

RenEngine Loader reads a Base64-decoded .key file for JSON config:

FieldValueDescription
filenameZt5qwYUCFL.txtXOR-encoded archive name
passwordeAX7G6bTTXOR decryption key
exec_fileW8CPbGQI.exeFile to launch
sandboxfalseEnables checks
pubt11_asmAnalytics tag
final_zip_nameInstsatp_*Unused (future?)

High-Impact Threat

The RenEngine Loader campaign is an advanced threat that represents a growing trend in modular malware delivery. Unlike simple “grab-and-go” infections, this campaign involves a carefully crafted, multi-stage process that includes payloads capable of evolving.

Attack overview (Source: cyderes)
Attack overview (Source: cyderes)

The use of legitimate game launchers to deliver malicious payloads demonstrates the increasing sophistication of cybercriminals, who now rely on trusted applications to bypass traditional security measures.

Key HijackLoader modules (by CRC):

ModulePurposeCRC
ANTIVMVM detection0x4DAD7707
AVDATAAV info0x78B783CA
CUSTOMINJECTInjection (32-bit)0x6703F815
modUAC64UAC bypass (64-bit)0xC97832F9
ti64Profiling (64-bit)0x2AB77DB8

According to Cyderes, the RenEngine Loader campaign represents an advanced threat that requires a shift in how security systems detect and defend against malware.

Its use of legitimate software and sophisticated techniques, such as encrypted payloads, environment checks, and modular loaders, makes it difficult for traditional security measures to detect.

As this campaign evolves, it highlights the need for more robust detection strategies focused on suspicious application behaviors and unusual file packaging.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

The post RenEngine Loader Uses Complex Chain To Bypass Security appeared first on Cyber Security News.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading