Security researchers reported a large-scale malware distribution campaign using pirated games and modified Ren’Py engine launchers to deliver a Python-based loader dubbed RenEngine (detected by Kaspersky as Trojan.Python.Agent.nb / HEUR:Trojan.Python.Agent.gen). Victims are lured through “cracked” game downloads hosted on file-sharing services; when the game appears to stall at completion, embedded Python scripts execute, initiating the infection chain. Reporting attributes the campaign’s discovery to the Howler Cell Threat Research Team, with telemetry indicating broad global targeting and heavy victim concentration in India, the U.S., and Brazil.
Analysis indicates RenEngine performs initial execution and hands off to a more advanced HijackLoader stage after environment checks (including sandbox/virtualization and hypervisor detection). HijackLoader is described as using process doppelganging before deploying the final payload, ACR Stealer, which steals browser credentials/cookies, system information, clipboard data, and cryptocurrency wallet details. Separate long-term tracking notes RenEngine activity dating back to at least March 2025, when it was used to distribute Lumma Stealer, with current activity shifting to ACR Stealer as the primary payload.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
In February 2026, researchers from Kaspersky and Howler Cell publicly documented the campaign's mechanics, including fake loading screens, Python-based anti-analysis logic, process doppelganging, and data theft from browsers, clipboards, and cryptocurrency wallets. They also reported the campaign had affected more than 400,000 machines globally, with major impact across countries including India, the U.S., Brazil, Russia, Spain, Turkey, and Germany.
Researchers said more recent RenEngine intrusions changed final payloads from Lumma to ACR Stealer, with Vidar also observed in some cases. The infection chain used sandbox checks, DLL hijacking, and HijackLoader to inject the stealer into legitimate Windows processes.
By April 2025, an ongoing mass malware campaign was using modified Ren'Py-based game launchers bundled with pirated titles to infect victims worldwide. The operation spread through piracy and gaming sites plus redirect chains to infected archives.
Kaspersky reported first seeing the previously undocumented RenEngine loader in the wild in March 2025. Early activity used trojanized pirated games and software to deliver Lumma Stealer.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 47 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurelist.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.