Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Fake Game Apps Deliver Multi-Stage Infostealers, Steal Crypto and Passwords
July 21, 2026
Qilin Ransomware Claims 1,358 Victims, Global Attacks Soar
July 21, 2026
Hackers Hijack Government Websites to Deliver Malware via Trusted Links
July 21, 2026
Home/Threats/Fake Game Apps Deliver Multi-Stage Infostealers, Steal Crypto and Passwords
Threats

Fake Game Apps Deliver Multi-Stage Infostealers, Steal Crypto and Passwords

Key Takeaways Cybercriminals are distributing multi-stage infostealers disguised as game downloads, mods, and cracks for Windows systems. The attack chain leverages the RenPy game engine and...

Marcus Rodriguez
Marcus Rodriguez
July 21, 2026 3 Min Read
3 0

Key Takeaways

  • Cybercriminals are distributing multi-stage infostealers disguised as game downloads, mods, and cracks for Windows systems.
  • The attack chain leverages the RenPy game engine and legitimate Windows utilities like MSBuild to evade detection.
  • The primary payload, Amatera Stealer, exfiltrates sensitive data including passwords, cryptocurrency wallet information, browser data, and local files.
  • Attackers are employing sophisticated techniques like EtherHiding, which stores command-and-control server addresses on the Ethereum blockchain, to complicate takedowns.
  • Users should only download software from official sources and organizations should implement strict software policies and monitor for anomalous activity.

Hackers Deploy Multi-Stage Infostealers via Fake Game Downloads

A sophisticated new campaign is leveraging fraudulent game downloads to infect Windows computers with a multi-stage information stealer. Threat actors are masquerading malicious archives as popular games, modifications, and software cracks, capitalizing on the demand for free or hard-to-find digital content.

Table Of Content

  • Key Takeaways
  • Hackers Deploy Multi-Stage Infostealers via Fake Game Downloads
  • The RenPy Loader Attack Chain
  • Credentials and Wallets at Risk

Upon execution, these seemingly innocuous downloaded archives initiate a stealthy infection process. While a user might observe a legitimate-looking loading or installation screen, a complex sequence of hidden programs is secretly deploying Amatera Stealer. This potent malware is engineered to pilfer a wide array of sensitive data, including passwords, browser information, cryptocurrency wallet details, messaging app data, and local files, as detailed in a recent analysis by researchers.

The RenPy Loader Attack Chain

The infection begins when a user executes a file named “Setup.exe” from a downloaded archive. This file initiates RenPy Loader, a sophisticated multi-stage framework that weaponizes the legitimate RenPy open-source game development engine. By embedding malicious Python code within a seemingly benign gaming package, the attackers cleverly disguise their true intent.

The initial stage of RenPy Loader performs anti-analysis checks to detect virtual environments. It then decrypts a hidden ZIP archive and extracts its contents into a temporary directory. To further aid its stealth, it removes the “Mark of the Web” protection from the extracted files, a security feature that flags files downloaded from the internet. Subsequently, it uses the legitimate Windows utility forfiles.exe to launch a batch file, effectively turning a routine installer into the gateway for a more extensive malicious operation.

This batch file then invokes MSBuild, another legitimate Windows build component, to load a compromised .NET library named Nancy. This modified library is responsible for decrypting further data, manipulating network settings, executing anti-forensics measures, and launching yet another hidden component. This technique of abusing trusted Windows utilities like MSBuild to mask malicious activity is a common evasive maneuver, as Malwarebytes said in a report.

The subsequent downloader, GollopDevest.dll, employs an advanced technique known as EtherHiding. This method retrieves its command-and-control (C2) server address from data embedded within the Ethereum blockchain, rather than storing it directly within the malware. This innovative approach significantly complicates detection and takedown efforts, a tactic previously observed in similar blockchain-based malware campaigns. Finally, GollopDevest.dll downloads and decrypts the ultimate payload: Amatera Stealer.

Credentials and Wallets at Risk

Amatera Stealer is designed to harvest information that can be quickly monetized or used for further illicit access. This includes browser passwords, cookies, and session data, which can grant attackers unauthorized entry into email, social media, financial services, and even corporate systems without requiring direct credential input. Furthermore, the theft of cryptocurrency wallets, browser extensions, messaging app data, and local files can lead to immediate and irreversible financial losses for individuals and pose significant risks to organizations.

It is important to note that the final payload delivered by RenPy Loader is not static. Researchers have previously documented the loader distributing other prominent malware families, such as HijackLoader and Lumma Stealer. This adaptability indicates that the operators can readily switch payloads to align with their specific campaign objectives. Users who have been tracking earlier Amatera Stealer activity or <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/32f4ada3-2d2d-4611-b9ae-d5f0638db429/Hackers-Turn-Fake-Games-Into-Multi-Stage-Infostealers-That-Steal-Passwords-and-Crypto-Wallets.pdf?AWSAccessKeyId=ASIA2F3EMEYEXG3EIVHM&Signature=6AE%2BvMkmf86ubXa2CCkDR%2FqrhYQ%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEPr%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCICHOthB7NGgxKUDtFMCUnbP9BSsejuc8jye%2BlJ6q

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwareSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Qilin Ransomware Claims 1,358 Victims, Global Attacks Soar

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Trump AI Safety Chief Resigns After Three Months
July 21, 2026
APT42 Targets Officials with AI Phishing, TAMECAT Malware
July 21, 2026
Critical GitHub Actions Flaw Backdoors AsyncAPI npm Packages with Miasma RAT
July 21, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
David kimber
David kimber
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us