# RenEngine Loader — Pirated Game Installers Abuse Ren'Py Python Launchers + DLL Side-Loading to Deliver HijackLoader and Lumma/ACR/Vidar Stealers

> RenEngine is a Python-based loader distributed inside cracked game and software installers (visual novels, CorelDRAW) on piracy sites that redirect to MEGA. Malicious Ren'Py engine scripts display a fake installation screen while XOR-decrypting and side-loading a malicious DLL (cc32290mt.dll) into a legitimate signed binary (Ahnenblatt4.exe), which loads HijackLoader and ultimately deploys the Lumma, ACR, and Vidar infostealers. Active since March 2025.

- **Published:** 2026-06-08T00:00:00Z
- **Last reviewed:** 2026-06-08T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0716
- **ID:** TL-2026-0716
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 31 (full data via the Threadlinqs MCP server — Purple tier)

## Description

RenEngine is a novel multi-stage loader observed in active distribution since March 2025 and analyzed publicly by Kaspersky's Securelist in February 2026. It abuses the Ren'Py visual-novel game engine's embedded Python runtime to bootstrap an infostealer infection chain that masquerades as a legitimate game or software installation.

Distribution: Operators seed cracked/pirated game and software installers (visual novels, CorelDRAW repacks) across piracy and warez sites (hentakugames[.]com, dodi-repacks[.]site, artistapirata[.]fit, gamesleech[.]com, parapcc[.]com, saglamindir[.]vip, awdescargas[.]pro, filedownloads[.]store). Victims are redirected to MEGA file-sharing to download a ZIP archive (e.g. setup_game_8246.zip) containing a Ren'Py-style launcher.

Stage 1 — Ren'Py Python abuse: The launcher runs modified Ren'Py Python scripts (e.g. __init.py__) that first call an is_sandboxed() function to evade automated analysis, then use an xor_decrypt_file routine to XOR-decrypt an embedded ZIP archive, unpack it into a .temp directory, and launch the unpacked payload — all while a fake game loading/installation screen is shown to the user. Kaspersky detects this component as Trojan.Python.Agent.nb / HEUR:Trojan.Python.Agent.gen.

Stage 2 — DLL side-loading: The unpacked payload contains a legitimate, validly signed binary — Ahnenblatt4.exe (a German genealogy application), sometimes renamed (e.g. DKsyVGUJ.exe) — alongside attacker-supplied DLLs. The malicious cc32290mt.dll contains a patched code snippet that intercepts control when the signed application launches (DLL search-order hijacking / signed binary proxy execution). Companion DLLs borlndmm.dll (a benign Borland memory manager) and dbghelp.dll are present; dbghelp.dll is overwritten in memory with decrypted shellcode. Kaspersky detects this as Trojan.Win32.Penguish / Trojan.Win32.DllHijacker (HijackLoader).

Stage 3 — HijackLoader: cc32290mt.dll decrypts first-stage shellcode from a file named gayal.asp and injects it into dbghelp.dll. HijackLoader stores XOR-encrypted configuration in the %TEMP% directory under a random filename, writing that filename into a system environment variable for reactivation. It spawns cmd.exe in suspended mode via its modCreateProcess module, maps dbghelp.dll using ZwCreateSection / ZwMapViewOfSection, decrypts a second stage from hap.eml into pla.dll, and finally injects the stealer payload into explorer.exe. Modules observed include ti (main module), rshell (shellcode launcher), ESAL (final payload executor), and auxiliary modules modTask, modUAC, modWriteFile, and COPYLIST.

Anti-analysis / anti-forensics: The loader writes payloads using the Windows Transactional NTFS (TxF) API, deliberately writing the MZ header last and with a delay, then rolls back the transaction to delete the temporary file — defeating signature scanning of intermediate artifacts and hindering forensic recovery.

Stage 4 — Infostealers: The final payload is one of three commodity stealers — Lumma (Trojan-PSW.Win32.Lumma.gen), ACR Stealer (Trojan-PSW.Win32.ACRstealer.gen), or Vidar — which harvest browser credentials, cookies/sessions, crypto wallets, and other sensitive local data. Lumma uses dead-drop resolvers via Steam Community profiles (steamcommunity[.]com/profiles/76561199822375128) and rotating C2 domains. As of February 2026, ACR Stealer has become a primary payload. Top affected regions are Russia, Brazil, Türkiye, Spain, and Germany.

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1189 Drive-by Compromise
- T1204.002 User Execution: Malicious File
- T1059.006 Command and Scripting Interpreter: Python
- T1106 Native API
- T1574.001 DLL
- T1218 System Binary Proxy Execution
- T1027 Obfuscated Files or Information
- T1055 Process Injection
- T1055.001 Process Injection: Dynamic-link Library Injection
- T1070.004 Indicator Removal: File Deletion
- T1497 Virtualization/Sandbox Evasion
- T1140 Deobfuscate/Decode Files or Information
- T1112 Modify Registry
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1005 Data from Local System
- T1102.001 Web Service: Dead Drop Resolver
- T1071.001 Application Layer Protocol: Web Protocols
- T1041 Exfiltration Over C2 Channel

## Sources

- [Active malicious campaign with the RenEngine loader (HijackLoader, Lumma, ACR)](https://securelist.com/renengine-campaign-with-hijackloader-lumma-and-acr-stealer/118891/)
- [MITRE ATT&CK — Hijack Execution Flow: DLL Search Order Hijacking (T1574.001)](https://attack.mitre.org/techniques/T1574/001/)
- [MITRE ATT&CK — System Binary Proxy Execution (T1218)](https://attack.mitre.org/techniques/T1218/)
- [MITRE ATT&CK — Process Injection (T1055)](https://attack.mitre.org/techniques/T1055/)
- [MITRE ATT&CK — Native API (T1106)](https://attack.mitre.org/techniques/T1106/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0716
