RenEngine Loader is a previously undocumented malware loader used in large-scale campaigns (observed since at least April/March 2025) to deliver next-stage payloads, notably ACR Stealer and Lumma Stealer. Cyderes and Cato Networks reported RenEngine Loader and another loader (Foxveil) being used to deliver follow-on payloads; in RenEngine Loader intrusions, it commonly stages a secondary loader referred to as Hijack Loader/HijackLoader, which then launches the final stealer payload.
Distribution and infection vector: RenEngine Loader has been delivered via illegally modified/trojanized game installers distributed on piracy platforms, including pirated copies of popular games (e.g., Assassin’s Creed, FIFA, Far Cry). The malicious logic is concealed within Ren’Py launchers; when the victim installs and launches the trojanized game, a hidden Python script executes to initiate the loader chain.
Behavior and capabilities: RenEngine Loader performs sandbox checks before executing the next stage (HijackLoader). HijackLoader adds anti-analysis measures (including GPU virtualization checks and hypervisor detection) and uses process doppelganging prior to launching the final payload (e.g., ACR Stealer). In separate reporting, RenEngine Loader was also observed in delivery chains (e.g., via game cheats and pirated software such as CorelDRAW) that ultimately deployed Lumma Stealer through Hijack Loader.
Impact/targeting: Reporting cited more than 400,000 machines targeted/impacted globally. The most targeted countries reported include India, the United States, and Brazil; other telemetry cited impacts in Russia, Brazil, Turkey, Spain, Germany, Mexico, Algeria, Egypt, Italy, and France.
Associated payloads (as described in the content): ACR Stealer is delivered via HijackLoader and is described as exfiltrating browser credentials and cookies, system information/details, clipboard contents, and cryptocurrency wallet data.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Run a full Windows malware scan. Scan the original archive, Downloads, Temp, AppData, startup locations, scheduled tasks, and browser-related data.
If you opened the suspicious Setup.exe , saw a fake progress window, or noticed a brief Command Prompt window, treat the computer as potentially compromised... The .BAT suffix does not mean the entire infection is one batch file. It identifies one script-based stage inside a larger chain... The extracted material included a BAT file and MSBuild project files.
The suspicious pattern is MSBuild starting from a newly extracted game-installer directory, reading unexpected project files, loading code from a user-writable path, and then making network connections or spawning later stages. MITRE tracks this type of abuse as Trusted Developer Utilities Proxy Execution: MSBuild.
"distributed via a heavily obfuscated Inno Setup installer"; "Delivered via a downloader in a ZIP archive"; "illegally modified game installers distributed via piracy platforms"
The suspicious pattern is MSBuild starting from a newly extracted game-installer directory, reading unexpected project files, loading code from a user-writable path, and then making network connections or spawning later stages. MITRE tracks this type of abuse as Trusted Developer Utilities Proxy Execution: MSBuild.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader observed since March 2025 distributing Lumma Stealer via game-cheat/pirated-software lures; stages Hijack Loader as a secondary loader which then deploys Lumma Stealer.
Loader active since April 2025, distributed via illegally modified game installers on piracy platforms; decrypts/stages payloads and hands off execution to Hijack Loader as a modular second stage, with the end goal of deploying ACR Stealer.
Loader distributed via trojanized/pirated game installers; decrypts and stages payloads, then transfers execution to Hijack Loader as a second stage; used to ultimately deploy an information stealer (ACR Stealer).
Loader malware embedded in Ren'Py launchers of pirated games; executes hidden Python to perform sandbox checks and then runs a more advanced HijackLoader variant to ultimately deliver ACR Stealer.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.