Threat reportMalwareTL-2026-0716

RenEngine Loader — Pirated Game Installers Abuse Ren'Py Python Launchers + DLL Side-Loading to Deliver HijackLoader and Lumma/ACR/Vidar Stealers

highACTIVE

RenEngine Loader (TL-2026-0716), also tracked as RenEngine, is a high-severity malware campaign, first published 2026-06-08. It has no confirmed attribution, affects Ren'Py (abused) Ren'Py visual-novel engine launchers (trojanized), maps to 19 MITRE ATT&CK techniques (T1005, T1027, T1041), and is covered by 9 detection rules and 31 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
31Indicators of compromise

Key facts for TL-2026-0716

Threat ID
TL-2026-0716
Also known as
RenEngine, RenEngine Loader
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
consumer, gaming, education
Target regions
Russia, Brazil, Türkiye, Spain, Germany
Detection rules
9
Indicators of compromise
31

Malware and tooling in RenEngine Loader

Malware and tooling: ACR Stealer, HijackLoader, Lumma, Vidar

How RenEngine Loader works

RenEngine is a Python-based loader distributed inside cracked game and software installers (visual novels, CorelDRAW) on piracy sites that redirect to MEGA. Malicious Ren'Py engine scripts display a fake installation screen while XOR-decrypting and side-loading a malicious DLL (cc32290mt.dll) into a legitimate signed binary (Ahnenblatt4.exe), which loads HijackLoader and ultimately deploys the Lumma, ACR, and Vidar infostealers. Active since March 2025.

RenEngine is a novel multi-stage loader observed in active distribution since March 2025 and analyzed publicly by Kaspersky's Securelist in February 2026. It abuses the Ren'Py visual-novel game engine's embedded Python runtime to bootstrap an infostealer infection chain that masquerades as a legitimate game or software installation.

Distribution: Operators seed cracked/pirated game and software installers (visual novels, CorelDRAW repacks) across piracy and warez sites (hentakugames[.]com, dodi-repacks[.]site, artistapirata[.]fit, gamesleech[.]com, parapcc[.]com, saglamindir[.]vip, awdescargas[.]pro, filedownloads[.]store). Victims are redirected to MEGA file-sharing to download a ZIP archive (e.g. setup_game_8246.zip) containing a Ren'Py-style launcher.

Stage 1 — Ren'Py Python abuse: The launcher runs modified Ren'Py Python scripts (e.g. __init.py__) that first call an is_sandboxed() function to evade automated analysis, then use an xor_decrypt_file routine to XOR-decrypt an embedded ZIP archive, unpack it into a .temp directory, and launch the unpacked payload — all while a fake game loading/installation screen is shown to the user. Kaspersky detects this component as Trojan.Python.Agent.nb / HEUR:Trojan.Python.Agent.gen.

Stage 2 — DLL side-loading: The unpacked payload contains a legitimate, validly signed binary — Ahnenblatt4.exe (a German genealogy application), sometimes renamed (e.g. DKsyVGUJ.exe) — alongside attacker-supplied DLLs. The malicious cc32290mt.dll contains a patched code snippet that intercepts control when the signed application launches (DLL search-order hijacking / signed binary proxy execution). Companion DLLs borlndmm.dll (a benign Borland memory manager) and dbghelp.dll are present; dbghelp.dll is overwritten in memory with decrypted shellcode. Kaspersky detects this as Trojan.Win32.Penguish / Trojan.Win32.DllHijacker (HijackLoader).

Stage 3 — HijackLoader: cc32290mt.dll decrypts first-stage shellcode from a file named gayal.asp and injects it into dbghelp.dll. HijackLoader stores XOR-encrypted configuration in the %TEMP% directory under a random filename, writing that filename into a system environment variable for reactivation. It spawns cmd.exe in suspended mode via its modCreateProcess module, maps dbghelp.dll using ZwCreateSection / ZwMapViewOfSection, decrypts a second stage from hap.eml into pla.dll, and finally injects the stealer payload into explorer.exe. Modules observed include ti (main module), rshell (shellcode launcher), ESAL (final payload executor), and auxiliary modules modTask, modUAC, modWriteFile, and COPYLIST.

Anti-analysis / anti-forensics: The loader writes payloads using the Windows Transactional NTFS (TxF) API, deliberately writing the MZ header last and with a delay, then rolls back the transaction to delete the temporary file — defeating signature scanning of intermediate artifacts and hindering forensic recovery.

Stage 4 — Infostealers: The final payload is one of three commodity stealers — Lumma (Trojan-PSW.Win32.Lumma.gen), ACR Stealer (Trojan-PSW.Win32.ACRstealer.gen), or Vidar — which harvest browser credentials, cookies/sessions, crypto wallets, and other sensitive local data. Lumma uses dead-drop resolvers via Steam Community profiles (steamcommunity[.]com/profiles/76561199822375128) and rotating C2 domains. As of February 2026, ACR Stealer has become a primary payload. Top affected regions are Russia, Brazil, Türkiye, Spain, and Germany.

MITRE ATT&CK techniques used in TL-2026-0716

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection; T1055.001 Process Injection: Dynamic-link Library Injection; T1070.004 Indicator Removal: File Deletion; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.006 Command and Scripting Interpreter: Python; T1106 Native API; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102.001 Web Service: Dead Drop Resolver

Persistence

T1112 Modify Registry

Initial Access

T1189 Drive-by Compromise

Credential Access

T1555.003 Credentials from Password Stores: Credentials from Web Browsers

stealth

T1574.001 DLL

Resource Development

T1583 Acquire Infrastructure

Affected products and versions in RenEngine Loader

  • Ren'Py (abused) — Ren'Py visual-novel engine launchers (trojanized)
    Vulnerable versions: trojanized cracked installers
  • Ahnenblatt (abused legitimate signed binary) — Ahnenblatt4.exe genealogy application
    Vulnerable versions: used as DLL side-loading host
  • Microsoft — Windows (victim endpoints)
    Vulnerable versions: Windows 10; Windows 11

Remediation for RenEngine Loader

Immediate actions

  • Block the listed distribution and C2 domains at the web proxy and DNS resolver
  • Hunt for Ahnenblatt4.exe / DKsyVGUJ.exe executing from user-writable or .temp directories
  • Alert on cc32290mt.dll, gayal.asp, hap.eml, and pla.dll artifacts in %TEMP% or extraction folders
  • Quarantine hosts where explorer.exe spawned cmd.exe in suspended state followed by stealer network beacons

Workarounds

  • Restrict execution from %TEMP% and per-user AppData via AppLocker/WDAC
  • Monitor and restrict creation of system environment variables by non-admin processes

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL side-loading and Transactional NTFS payload writes
  • Enforce application allowlisting to prevent execution of unsigned/relocated signed binaries from user paths
  • Block downloads from known piracy/warez and MEGA links via web filtering policy
  • User awareness training on the risk of cracked/pirated software

Weaknesses (CWE) in RenEngine Loader

CWE-427, CWE-426

Timeline of RenEngine Loader

  • First RenEngine samples observed in the wild distributing the Lumma stealer via cracked game installers.
  • Campaign expands distribution across multiple piracy/warez sites and MEGA file-sharing redirects.
  • ACR Stealer becomes a primary final payload alongside Lumma and Vidar in observed February 2026 infections.
  • Kaspersky Securelist publishes full technical analysis of the RenEngine loader campaign.
  • Threadlinqs Intelligence documents the threat with full MITRE mapping, IOCs, and detection coverage.

Sources cited for RenEngine Loader

Detection coverage for TL-2026-0716

As of 2026-06-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0716 across Splunk SPL, Microsoft KQL and Sigma, covering 31 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
31 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats