Threat reportMalwareTL-2026-0716
RenEngine Loader — Pirated Game Installers Abuse Ren'Py Python Launchers + DLL Side-Loading to Deliver HijackLoader and Lumma/ACR/Vidar Stealers
RenEngine Loader (TL-2026-0716), also tracked as RenEngine, is a high-severity malware campaign, first published 2026-06-08. It has no confirmed attribution, affects Ren'Py (abused) Ren'Py visual-novel engine launchers (trojanized), maps to 19 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 31 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 19MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 31Indicators of compromise
Key facts for TL-2026-0716
- Threat ID
- TL-2026-0716
- Also known as
- RenEngine, RenEngine Loader
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- consumer, gaming, education
- Target regions
- Russia, Brazil, Türkiye, Spain, Germany
- Detection rules
- 9
- Indicators of compromise
- 31
Malware and tooling in RenEngine Loader
Malware and tooling: ACR Stealer, HijackLoader, Lumma, Vidar
How RenEngine Loader works
RenEngine is a Python-based loader distributed inside cracked game and software installers (visual novels, CorelDRAW) on piracy sites that redirect to MEGA. Malicious Ren'Py engine scripts display a fake installation screen while XOR-decrypting and side-loading a malicious DLL (cc32290mt.dll) into a legitimate signed binary (Ahnenblatt4.exe), which loads HijackLoader and ultimately deploys the Lumma, ACR, and Vidar infostealers. Active since March 2025.
RenEngine is a novel multi-stage loader observed in active distribution since March 2025 and analyzed publicly by Kaspersky's Securelist in February 2026. It abuses the Ren'Py visual-novel game engine's embedded Python runtime to bootstrap an infostealer infection chain that masquerades as a legitimate game or software installation.
Distribution: Operators seed cracked/pirated game and software installers (visual novels, CorelDRAW repacks) across piracy and warez sites (hentakugames[.]com, dodi-repacks[.]site, artistapirata[.]fit, gamesleech[.]com, parapcc[.]com, saglamindir[.]vip, awdescargas[.]pro, filedownloads[.]store). Victims are redirected to MEGA file-sharing to download a ZIP archive (e.g. setup_game_8246.zip) containing a Ren'Py-style launcher.
Stage 1 — Ren'Py Python abuse: The launcher runs modified Ren'Py Python scripts (e.g. __init.py__) that first call an is_sandboxed() function to evade automated analysis, then use an xor_decrypt_file routine to XOR-decrypt an embedded ZIP archive, unpack it into a .temp directory, and launch the unpacked payload — all while a fake game loading/installation screen is shown to the user. Kaspersky detects this component as Trojan.Python.Agent.nb / HEUR:Trojan.Python.Agent.gen.
Stage 2 — DLL side-loading: The unpacked payload contains a legitimate, validly signed binary — Ahnenblatt4.exe (a German genealogy application), sometimes renamed (e.g. DKsyVGUJ.exe) — alongside attacker-supplied DLLs. The malicious cc32290mt.dll contains a patched code snippet that intercepts control when the signed application launches (DLL search-order hijacking / signed binary proxy execution). Companion DLLs borlndmm.dll (a benign Borland memory manager) and dbghelp.dll are present; dbghelp.dll is overwritten in memory with decrypted shellcode. Kaspersky detects this as Trojan.Win32.Penguish / Trojan.Win32.DllHijacker (HijackLoader).
Stage 3 — HijackLoader: cc32290mt.dll decrypts first-stage shellcode from a file named gayal.asp and injects it into dbghelp.dll. HijackLoader stores XOR-encrypted configuration in the %TEMP% directory under a random filename, writing that filename into a system environment variable for reactivation. It spawns cmd.exe in suspended mode via its modCreateProcess module, maps dbghelp.dll using ZwCreateSection / ZwMapViewOfSection, decrypts a second stage from hap.eml into pla.dll, and finally injects the stealer payload into explorer.exe. Modules observed include ti (main module), rshell (shellcode launcher), ESAL (final payload executor), and auxiliary modules modTask, modUAC, modWriteFile, and COPYLIST.
Anti-analysis / anti-forensics: The loader writes payloads using the Windows Transactional NTFS (TxF) API, deliberately writing the MZ header last and with a delay, then rolls back the transaction to delete the temporary file — defeating signature scanning of intermediate artifacts and hindering forensic recovery.
Stage 4 — Infostealers: The final payload is one of three commodity stealers — Lumma (Trojan-PSW.Win32.Lumma.gen), ACR Stealer (Trojan-PSW.Win32.ACRstealer.gen), or Vidar — which harvest browser credentials, cookies/sessions, crypto wallets, and other sensitive local data. Lumma uses dead-drop resolvers via Steam Community profiles (steamcommunity[.]com/profiles/76561199822375128) and rotating C2 domains. As of February 2026, ACR Stealer has become a primary payload. Top affected regions are Russia, Brazil, Türkiye, Spain, and Germany.
MITRE ATT&CK techniques used in TL-2026-0716
Collection
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection; T1055.001 Process Injection: Dynamic-link Library Injection; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.006 Command and Scripting Interpreter: Python; T1106 Native API; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1102.001 Web Service: Dead Drop Resolver
Persistence
Initial Access
Credential Access
T1555.003 Credentials from Password Stores: Credentials from Web Browsers
stealth
Resource Development
Affected products and versions in RenEngine Loader
- Ren'Py (abused) — Ren'Py visual-novel engine launchers (trojanized)
Vulnerable versions: trojanized cracked installers - Ahnenblatt (abused legitimate signed binary) — Ahnenblatt4.exe genealogy application
Vulnerable versions: used as DLL side-loading host - Microsoft — Windows (victim endpoints)
Vulnerable versions: Windows 10; Windows 11
Remediation for RenEngine Loader
Immediate actions
- Block the listed distribution and C2 domains at the web proxy and DNS resolver
- Hunt for Ahnenblatt4.exe / DKsyVGUJ.exe executing from user-writable or .temp directories
- Alert on cc32290mt.dll, gayal.asp, hap.eml, and pla.dll artifacts in %TEMP% or extraction folders
- Quarantine hosts where explorer.exe spawned cmd.exe in suspended state followed by stealer network beacons
Workarounds
- Restrict execution from %TEMP% and per-user AppData via AppLocker/WDAC
- Monitor and restrict creation of system environment variables by non-admin processes
Longer-term hardening
- Deploy EDR with behavioral detection for DLL side-loading and Transactional NTFS payload writes
- Enforce application allowlisting to prevent execution of unsigned/relocated signed binaries from user paths
- Block downloads from known piracy/warez and MEGA links via web filtering policy
- User awareness training on the risk of cracked/pirated software
Weaknesses (CWE) in RenEngine Loader
Timeline of RenEngine Loader
- First RenEngine samples observed in the wild distributing the Lumma stealer via cracked game installers.
- Campaign expands distribution across multiple piracy/warez sites and MEGA file-sharing redirects.
- ACR Stealer becomes a primary final payload alongside Lumma and Vidar in observed February 2026 infections.
- Kaspersky Securelist publishes full technical analysis of the RenEngine loader campaign.
- Threadlinqs Intelligence documents the threat with full MITRE mapping, IOCs, and detection coverage.
Sources cited for RenEngine Loader
Detection coverage for TL-2026-0716
As of 2026-06-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0716 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.