Surge in AI-Driven Phishing Attacks and QR Code Quishing in 2025 Spam and Phishing Report
## Malware Distribution via Pirated Software
Malware Distribution via Pirated Software
The use of pirated games and cracked applications for distributing malicious software remains an effective tactic employed by cybercriminals. This approach exploits users' desire for free access to premium content, facilitating the delivery of complex threats to personal devices.
A recent campaign highlights this trend, using a sophisticated loader hidden within modified game launchers to execute a multi-stage infection process. This loader uses the Ren'Py visual novel engine, making the malicious files appear as legitimate game components.
Users downloading compromised packages are redirected through multiple websites before reaching a file-hosting service. Upon execution, the malware operates under the guise of a standard loading screen, masking malicious activity.
Identified as RenEngine, this loader family has been active since March 2025. Initially used to distribute the Lumma stealer, it has evolved to deliver ACR Stealer, expanding targets to include users seeking pirated graphics software and productivity tools. These stealers extract passwords, cryptocurrency wallets, and session cookies from victim machines.
The use of pirated games and cracked applications for distributing malicious software remains an effective tactic employed by cybercriminals.
Incidents have been recorded in multiple countries, including Russia, Brazil, and Spain. The modular loader design complicates detection and blocking by standard security solutions, posing significant security challenges.
Infection Mechanism and Evasion Tactics
RenEngine's technical sophistication allows it to avoid detection during initial execution. The attack initiates with Python scripts simulating a game loading process while performing environment checks. It uses the is_sandboxed function to detect security analysis and xor_decrypt_file to unpack the next payload stage from an encrypted archive.
Following decryption, DLL hijacking loads the HijackLoader module by overwriting dbghelp.dll , injecting malicious code into trusted processes. This enables seamless malware operation, harvesting sensitive data while remaining undetected.
For further technical details, visit Securelist .
Based on reporting by Cyber Security News.
