Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Pwn2Own Day 2: Microsoft Exchange, Win Windows Cursor
May 16, 2026
JDownloader Compromised: Malicious Windows & Linux
May 16, 2026
Malicious JPEG Images Exploit PHP Memory Safety Could Trigger
May 16, 2026
Home/Threats/RenEngine Loader Bypasses Security Controls via Stealth
Threats

RenEngine Loader Bypasses Security Controls via Stealth

A new HijackLoader variant has emerged, incorporating advanced anti-analysis modules designed to bypass security controls. These capabilities include checks for GPUs, hypervisor names, and VM-linked...

Emy Elsamnoudy
Emy Elsamnoudy
February 6, 2026 2 Min Read
8 0

A new HijackLoader variant has emerged, incorporating advanced anti-analysis modules designed to bypass security controls. These capabilities include checks for GPUs, hypervisor names, and VM-linked MAC addresses.

Together, RenEngine and HijackLoader form a dual-loader setup that helps the operators swap payloads quickly as defenses change.

A typical run starts when a user executes the pirated installer, then RenEngine decrypts and launches the second stage.

Attack overview (Source - Cyderes)
Attack overview (Source – Cyderes)

HijackLoader is then introduced through DLL side-loading and module stomping, and the final payload observed in this chain is ACR Stealer.

ACR Stealer is built to collect browser passwords and cookies, crypto wallet data, and other system details, then send it to attacker infrastructure. Some chains have also delivered other stealers, such as Vidar.

Infection mechanism inside Ren’Py

Infection begins in the game folder, where Instaler.exe is a real Ren’Py launcher but is abused to run a compiled script from archive.rpa.

The build strips plain .rpy files and keeps only .rpyc, reducing visibility during scans.

Files and directories dropped by zip (Source - Cyderes)
Files and directories dropped by zip (Source – Cyderes)

Next, RenEngine reads a local .key file, Base64-decodes it into JSON, and uses the password value to XOR-decrypt an embedded archive before running the next executable.

RenEngine Loader configuration (Source - Cyderes)
RenEngine Loader configuration (Source – Cyderes)

When sandbox checks are enabled, the loader scores the environment and exits silently if it believes it is running in a virtual machine.

For defense, treat piracy installers and mods as high risk and block them where possible.

Watch for Ren’Py launchers unpacking RPA content, Base64/XOR staging, and aggressive VM checks, then correlate with suspicious DLL side-loading and sudden credential theft traffic across endpoints today.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackSecurity

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

China-Nexus Hackers Hijacking Linux-Based Devices to Manipulate

Next Post

New Odyssey Stealer Wave Actively Targets macOS Users

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Android 16 VPN Bypass Exposes User IP Lets Malicious
May 16, 2026
OpenClaw Chain Flaws Expose 245 Vulnerabilities Public
May 15, 2026
Gunra Ransomware RaaS Expands After Conti Locker Operations Shifting
May 15, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Sarah simpson
Sarah simpson
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us