RenEngine Loader: Catch'Em All - Inside a 1.6 Million-Victim Global  Stealer Campaign Hidden in a Game Engine - Cybersecurity Conference

RenEngine Loader: Catch’Em All – Inside a 1.6 Million-Victim Global  Stealer Campaign Hidden in a Game Engine

The Cyderes Howler Cell Threat Research Team presents the discovery and full technical dissection of RenEngine Loader, a previously unreported malware loader behind one of the largest stealer campaigns of 2025–2026. With over 1.6 million confirmed victims across 200+ countries, India and the United States ranking as the top two affected nations, and 5,000 to 6,000 new infections daily, this campaign
remains active and growing.

RenEngine hides malicious logic inside .rpyc script files of the legitimate Ren’Py game engine, packaged within .rpa archives that resist extraction by tools like 7-Zip and WinRAR, defeating most static analysis. It spreads through ZIP archives disguised as cracked game installers and piracy repacks, exploiting user trust at scale rather than software vulnerabilities.

On execution, a scoring-based environment validation checks GPU virtualisation, hypervisor presence, disk/RAM thresholds, and sandbox artefacts before proceeding. Payloads are decoded via layered Base64 and XOR routines, then handed off to HijackLoader via DLL sideloading (dbghelp.dll, shell32.dll) and Module Stomping. HijackLoader’s 30+ modular capabilities include Heaven’s Gate (x86-to-x64 switching to bypass user-mode hooks), Call Stack Spoofing, and Process Doppelgänging for injection into legitimate processes. Final payloads are ACR Stealer, Lumma, and Vidar, distributed via a Stealer-as-a-Service model with C2 masked through Cloudflare and Supabase.

A standout discovery is attacker-embedded telemetry providing a rare operator-side view of real-time infection metrics. The victim attribution methodology underpinning our 1.6 million figure is intentionally withheld from public disclosure and will be presented exclusively at this conference.

Attendees receive a full execution chain walkthrough, YARA rules, EDR hunting queries, and behavioural detection strategies for disrupting loader-to-loader chains that abuse trusted application frameworks.

Rahul Ramesh

Rahul Ramesh is a Senior Threat Researcher with Cyderes Howler Cell, specializing in malware analysis, threat hunting, and threat intelligence. He has previously contributed to security research at K7 Computing and SentinelOne.

His work focuses on identifying and researching emerging threats, with a particular interest in malware reverse engineering, tracking evolving threat actor payloads and techniques, and contributing to the detection of emerging threats.

Reegun Richard Jayapaul

I lead threat research at Cyderes, focusing on malware analysis, reverse engineering, threat hunting, vulnerability research, and cyber threat intelligence.

Over the past 15+ years, I have worked across incident response, malware research, APT tracking, detection engineering, offensive security, and public vulnerability research. My work has supported investigations, improved detection capabilities, informed customer defences, and contributed to research on active campaigns and emerging attacker tradecraft.

At Cyderes Howler Cell, I help lead research into real-world threats, including malware campaigns, Windows vulnerabilities, supply-chain abuse, updater trust issues, and adversary infrastructure. I regularly work with researchers, threat hunters, incident responders, and leadership teams to turn technical findings into practical defensive guidance.

My past research includes work on GoldenSpy and GoldenHelper, Microsoft Teams security issues, LOLBAS abuse techniques, and multiple public threat investigations. I also contribute to the LOLBAS project and share research through public reports, conference talks, and community collaboration.