RedEngine Loader is a Windows-focused, multi-stage loader and information-stealing malware operation reported as active since at least early 2025. It is distributed via pirated video games using customized installers. The loader performs environment checks intended to detect virtualization/sandboxing before proceeding, and is described as using analysis-evasion/obfuscation techniques while gradually deploying additional components.
Capabilities attributed in the source include theft of sensitive data such as saved browser passwords, browser/session data, and cryptocurrency-related information, with exfiltration to attacker-controlled servers.
High-confidence indicators and detection content mentioned include a YARA rule named “RenEngine_Loader_String_IOCs,” sample hashes 645d7c74823d39394c46c942955960dd, 1001e0a83d0a622828613a4a66735ce0, and 17de79f44b8af959b3ae9e486ade55b2, and infrastructure indicators domain dodi-repacks.site and IP address 78.40.193.126. The report also maps RedEngine Loader activity to multiple MITRE ATT&CK techniques, including user execution (T1204.002), command and scripting interpreter (T1059.006), obfuscation (T1027), virtualization/sandbox evasion (T1497), process injection (T1055), scheduled task (T1053.005), credential theft from browsers (T1555.003), and exfiltration over C2/web protocols (T1071.001/T1041). No specific threat-actor attribution is stated in the provided content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage loader distributed via pirated video game installers; performs sandbox checks, gradually deploys additional components, and ultimately steals data (browser passwords/session data and cryptocurrency-related information) for exfiltration to attacker-controlled infrastructure.
Multi-stage loader distributed via trojanized/pirated game installers; performs sandbox checks, gradually deploys additional components, and ultimately steals browser credentials/session data and cryptocurrency-related information, exfiltrating it to attacker-controlled infrastructure.
Multi-stage loader distributed via trojanized/pirated game installers; performs environment checks/evasion, gradually deploys additional components, and ultimately steals browser credentials/session data and cryptocurrency-related information for exfiltration to attacker-controlled infrastructure.
Multi-stage loader distributed via trojanized/pirated game installers; performs sandbox checks, gradually deploys additional components, and ultimately steals data (browser passwords/session data and cryptocurrency-related information) and exfiltrates it to attacker-controlled infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.