#renengine
-Global Telnet traffic drops ahead of vuln release, remains low
-New Crazy ransomware
-Netdragon botnet targets NAS devices
-New OysterLoader, RenEngine, and Foxveil loaders
-France takes down Storm-1516 sites
-Google says LLMs are now essential to APTs
-2026 vuln total expected close to 60k-100k
February 13, 2026 at 9:09 AM
If the radio silence continues I might just go through with creating the RenEngine fork.
September 18, 2025 at 7:07 PM
Oh I thought this was something extant, I understand now. What would RenEngine be a fork of?
September 18, 2025 at 7:36 PM
¿Cómo eliminar #malware al 100% de la instalación? Guía para limpiar #scripts maliciosos en videojuegos piratas | #Gaming www.newstecnicas.info.ve/2026/03/cibe...
¿Cómo eliminar malware al 100% de la instalación? Guía para limpiar scripts maliciosos en videojuegos piratas | #Gaming
Guía para eliminar scripts maliciosos en juegos piratas. Detectan malware RenEngine al 100% de la instalación en repacks este marzo de 2026.
www.newstecnicas.info.ve
March 14, 2026 at 10:07 AM
¿Cómo eliminar malware al 100% de la instalación? Guía para limpiar scripts maliciosos en videojuegos piratas | #Gaming www.newstecnicas.info.ve/2026/03/cibe...
¿Cómo eliminar malware al 100% de la instalación? Guía para limpiar scripts maliciosos en videojuegos piratas | #Gaming
Guía para eliminar scripts maliciosos en juegos piratas. Detectan malware RenEngine al 100% de la instalación en repacks este marzo de 2026.
www.newstecnicas.info.ve
March 11, 2026 at 2:14 PM
RenEngine Loader Using Stealthy Multi‑Stage Execution Chain to Bypass Security Controls
RenEngine Loader Using Stealthy Multi‑Stage Execution Chain to Bypass Security Controls
Cracked game installers are again being used as a delivery channel for credential theft, but the latest wave adds an unusual twist: the malicious code hides behind a Ren’Py game launcher. The loader, now tracked as RenEngine, arrives bundled with game repacks and mods that look normal and even run as expected, while quietly preparing the next stage of the attack chain. The campaign has been active since at least April 2025 and remains ongoing, reaching an estimated 400,000 victims worldwide. Telemetry reviewed by the researchers suggests about 5,000 new hits per day, with the highest concentrations in India, the United States, and Brazil. This scale matters because the initial lure relies on social trust inside piracy communities rather than a software vulnerability, making it hard to stop with patching alone. Cyderes researchers noted the malware after spotting malicious logic embedded in what looked like a legitimate Ren’Py-based launcher. In the same cases, they also analyzed a fresh HijackLoader variant that brings added anti‑analysis modules, including checks for GPUs, hypervisor names, and VM-linked MAC addresses. Together, RenEngine and HijackLoader form a dual-loader setup that helps the operators swap payloads quickly as defenses change. A typical run starts when a user executes the pirated installer, then RenEngine decrypts and launches the second stage. Attack overview (Source – Cyderes) HijackLoader is then introduced through DLL side-loading and module stomping, and the final payload observed in this chain is ACR Stealer. ACR Stealer is built to collect browser passwords and cookies, crypto wallet data, and other system details, then send it to attacker infrastructure. Some chains have also delivered other stealers, such as Vidar. Infection mechanism inside Ren’Py Infection begins in the game folder, where Instaler.exe is a real Ren’Py launcher but is abused to run a compiled script from archive.rpa. The build strips plain .rpy files and keeps only .rpyc, reducing visibility during scans. Files and directories dropped by zip (Source – Cyderes) Next, RenEngine reads a local .key file, Base64-decodes it into JSON, and uses the password value to XOR-decrypt an embedded archive before running the next executable. RenEngine Loader configuration (Source – Cyderes) When sandbox checks are enabled, the loader scores the environment and exits silently if it believes it is running in a virtual machine. For defense, treat piracy installers and mods as high risk and block them where possible. Watch for Ren’Py launchers unpacking RPA content, Base64/XOR staging, and aggressive VM checks, then correlate with suspicious DLL side-loading and sudden credential theft traffic across endpoints today. Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post RenEngine Loader Using Stealthy Multi‑Stage Execution Chain to Bypass Security Controls appeared first on Cyber Security News .
cybersecuritynews.com
February 6, 2026 at 1:17 PM
heads up to all of you VN readers, be careful with the VNs you play
www.pcmag.com/news/malware...
Malware Hidden in Pirated Games Infects 400,000 Devices
Security researchers uncover evidence that the Windows-based 'RenEngine loader' malware has infected around 30,000 users in the US alone.
www.pcmag.com
February 12, 2026 at 8:45 PM
¿Cómo eliminar #malware al 100% de la instalación? Guía para limpiar #scripts maliciosos en videojuegos piratas | #Gaming www.newstecnicas.info.ve/2026/03/cibe...
¿Cómo eliminar malware al 100% de la instalación? Guía para limpiar scripts maliciosos en videojuegos piratas | #Gaming
Guía para eliminar scripts maliciosos en juegos piratas. Detectan malware RenEngine al 100% de la instalación en repacks este marzo de 2026.
www.newstecnicas.info.ve
April 1, 2026 at 4:04 PM
Malware Oculto en Juegos y Programas Piratas Golpea a Usuarios en América Latina

El equipo de Threat Research de Kaspersky ha publicado un análisis técnico sobre RenEngine, un loader de malware que se distribuye a través de juegos modificados y software pirateado. Detectado por primera vez en…
Malware Oculto en Juegos y Programas Piratas Golpea a Usuarios en América Latina
El equipo de Threat Research de Kaspersky ha publicado un análisis técnico sobre RenEngine, un loader de malware que se distribuye a través de juegos modificados y software pirateado. Detectado por primera vez en marzo de 2025, la amenaza ha afectado a usuarios en varias regiones, incluida América Latina, y amplía el riesgo más allá de la comunidad gaming hacia quienes buscan programas sin licencia…
infosertecla.com
March 21, 2026 at 1:00 PM
¿Cómo eliminar #malware al 100% de la instalación? Guía para limpiar #scripts maliciosos en videojuegos piratas | #Gaming www.newstecnicas.info.ve/2026/03/cibe...
¿Cómo eliminar malware al 100% de la instalación? Guía para limpiar scripts maliciosos en videojuegos piratas | #Gaming
Guía para eliminar scripts maliciosos en juegos piratas. Detectan malware RenEngine al 100% de la instalación en repacks este marzo de 2026.
www.newstecnicas.info.ve
March 26, 2026 at 12:21 AM
¿Cómo eliminar malware al 100% de la instalación? Guía para limpiar scripts maliciosos en videojuegos piratas | #Gaming www.newstecnicas.info.ve/2026/03/cibe...
¿Cómo eliminar malware al 100% de la instalación? Guía para limpiar scripts maliciosos en videojuegos piratas | #Gaming
Guía para eliminar scripts maliciosos en juegos piratas. Detectan malware RenEngine al 100% de la instalación en repacks este marzo de 2026.
www.newstecnicas.info.ve
March 16, 2026 at 5:59 PM
¿Cómo eliminar #malware al 100% de la instalación? Guía para limpiar #scripts maliciosos en videojuegos piratas | #Gaming www.newstecnicas.info.ve/2026/03/cibe...
¿Cómo eliminar malware al 100% de la instalación? Guía para limpiar scripts maliciosos en videojuegos piratas | #Gaming
Guía para eliminar scripts maliciosos en juegos piratas. Detectan malware RenEngine al 100% de la instalación en repacks este marzo de 2026.
www.newstecnicas.info.ve
March 12, 2026 at 2:21 PM
Juegos gratis, datos robados: el nuevo ciberataque que avanza en América Latina

La amenaza, detectada por Kaspersky, utiliza instaladores aparentemente legítimos para descargar malware que roba información de los usuarios. El equipo de Threat Research de Kaspersky ha publicado un análisis técnico…
Juegos gratis, datos robados: el nuevo ciberataque que avanza en América Latina
La amenaza, detectada por Kaspersky, utiliza instaladores aparentemente legítimos para descargar malware que roba información de los usuarios. El equipo de Threat Research de Kaspersky ha publicado un análisis técnico sobre RenEngine, un loader de malware que se distribuye a través de juegos modificados y software pirateado. Detectado por primera vez en marzo de 2025, la amenaza ha afectado a usuarios en varias regiones, incluida América Latina, y amplía el riesgo más allá de la comunidad gaming hacia quienes buscan programas sin licencia.
www.estamosenlinea.com
March 25, 2026 at 6:00 PM
Il gioco è gratis, il malware no (e lo stai pagando carissimo)

📌 Link all'articolo : www.redhotcyber.com/post/il-...

#redhotcyber #news #malware #cybersecurity #sicurezzainformatica #hacking #minacceinformatiche #renengine
February 9, 2026 at 5:56 AM
Windows Malware Distributed Through Pirated Games Infects Over 400,000 Systems #Avast #malware #PCGames
Windows Malware Distributed Through Pirated Games Infects Over 400,000 Systems
  A Windows-focused malware operation spreading through pirated PC games has potentially compromised more than 400,000 devices worldwide, according to research released by Cyderes. The company identified the threat as “RenEngine loader” and reported that roughly 30,000 affected users are located in the United States alone. Investigators found the malicious code embedded inside cracked and repackaged versions of popular game franchises, including Far Cry, Need for Speed, FIFA, and Assassin’s Creed. The infected installers appear to function normally, allowing users to download and play the games. However, while the visible game content runs as expected, concealed code executes in parallel without the user’s awareness. Researchers traced part of the operation to a legitimate launcher built on Ren'Py, an engine commonly used for visual novel-style games. The attackers embedded harmful components within this launcher framework. When executed, the launcher decompresses archived game files as intended, but at the same time initiates the hidden malware routine. According to Cyderes, the campaign has been active since at least April of last year and remains ongoing. In October, the operators modified the malware to include an embedded telemetry URL. Each time the RenEngine loader runs, it connects to this address, allowing the attackers to log activity. Analysis of that telemetry endpoint enabled researchers to estimate overall infection levels, with the system recording between 4,000 and 10,000 visits per day. Telemetry data indicates that the largest concentration of victims is located in India, the United States, and Brazil. The US accounts for approximately 30,000 of the infected systems identified through this tracking mechanism. The loader’s primary function is to deliver additional malicious software onto compromised machines. In multiple cases, researchers observed it deploying a Windows-based information stealer known as ARC. This malware is designed to extract stored browser passwords, session cookies, cryptocurrency wallet information, autofill entries, clipboard data, and system configuration details. Cyderes also reported observing alternative payloads delivered through the same loader infrastructure, including Rhadamanthys stealer, Async RAT, and XWorm. These programs are capable of credential theft and, in some cases, remote system control, enabling attackers to monitor activity or manipulate infected devices. The investigation identified one distribution source, dodi-repacks[.]site, as hosting downloads containing the embedded malware. The domain has previously been associated with other malicious distribution activity. Detection remains limited at the initial infection stage. Public scan results from Google’s VirusTotal platform indicate that, aside from Avast, AVG, and Cynet, most antivirus engines currently do not flag the loader component as malicious. This detection gap increases the likelihood that users may remain unaware of compromise. Users who suspect infection are advised to run updated security scans immediately. If concerns persist, Windows System Restore may help revert the device to a prior clean state. In cases where compromise cannot be confidently removed, a full operating system reinstallation may be necessary. The findings reinforce a recurring cybersecurity risk: unauthorized software downloads frequently serve as a delivery channel for concealed malware capable of exposing personal data and granting attackers extended access to victim systems.
dlvr.it
February 20, 2026 at 6:21 PM
Far Cry / FIFA / Need for Speed / Assassin’s Creed などの海賊版にマルウェア混入

DODI Repacks 由来のPCゲームに仕込まれたマルウェア「RenEngine Loader」が拡散中。
2025年4月〜現在も継続、40万台以上感染。
Ren’Pyランチャー内に埋め込まれているとのこと
May 21, 2026 at 12:37 PM
ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories
ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories
thehackernews.com
February 12, 2026 at 12:31 PM
⚠️ Gamers beware! Pirated PC games like FIFA & Assassin's Creed are infecting systems with 'RenEngine' malware. Over 400k devices hit, dropping infostealers & RATs. Don't download cracked games! 🎮 #Malware #Gaming #CyberSecurity #Rhadamanthys

🌐 cyber[.]netsecops[.]io
Pirated PC Games Infect 400,000+ Devices with "RenEngine" Password-Stealing Malware
A malware campaign using pirated PC games has infected over 400,000 devices with the
cyber.netsecops.io
June 8, 2026 at 3:59 PM
RenEngine campaign infected 400,000 users via cracked games
RenEngine campaign infected 400,000 users via cracked games
Dual-stage RenEngine malware spreads via pirated AAA games, infecting 400,000+ systems worldwide with stealthy loaders and info-stealing payloads.
buff.ly
February 13, 2026 at 11:34 AM