RenEngine is a malware loader/downloader family identified by Securelist/Kaspersky as a distinct loader circulating since March 2025. It has been observed in mass campaigns distributing pirated games and cracked software, where it is delivered through modified Ren’Py engine-based game launchers and disguised hacked-game packages. Victims are redirected through multiple sites or file-hosting services to download trojanized archives; when executed, the launcher presents a fake or functioning loading/game screen while malicious activity runs in the background. RenEngine’s infection chain uses Python scripts for environment and sandbox checks, including an is_sandboxed function, and an xor_decrypt_file routine to decrypt and unpack later stages from an encrypted archive. It uses DLL hijacking, including abuse of dbghelp.dll and patched DLLs such as cc32290mt.dll, to launch HijackLoader, which then decrypts and injects the final payload into trusted processes such as explorer.exe, including via Windows NT APIs like ZwCreateSection and ZwMapViewOfSection and transactional file techniques to reduce on-disk artifacts. Earlier observed RenEngine activity delivered Lumma Stealer; later incidents delivered ACR Stealer, and Vidar was also observed in related campaigns. The stealers were described as targeting passwords, cryptocurrency wallets, and session cookies. Active incidents were recorded across multiple countries including Russia, Brazil, Spain, Turkey, and Germany. Separately, Kaspersky also reported RenEngine among the malware families distributed via malicious Steam Wallpaper Engine application wallpapers since late 2025, alongside DarkKomet, Lumma, and Vidar, in campaigns primarily affecting gamers in China and Russia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The app supports four wallpaper types, and one of them, the "application wallpaper," is a standalone executable Windows program that runs as the desktop background. That also makes it a pathway for third-party code to execute on a user's machine, which is exactly what attackers exploited.
"...leverages the structure of the Ren’Py visual novel engine, making the malicious files appear as legitimate components of the game."
"...inject malicious code into a trusted process... launch the final payload... within the memory space of a system process like explorer.exe."
"xor_decrypt_file for decrypting the malicious payload" / "configuration parameters are encrypted using XOR"
34 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader observed among payloads delivered through malicious Wallpaper Engine packages on Steam.
Loader used as one of the payloads delivered through malicious Steam Workshop wallpapers.
Loader malware distributed through malicious Wallpaper Engine projects in Steam Workshop.
Downloader malware observed being distributed via malicious Steam Workshop wallpapers.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.