TI Mindmap HUB
Threat Intelligence Report

RenEngine Loader and HijackLoader: Dual-Stage Attack Chain Fueling Stealer Campaigns

📅 February 6, 2026 📰 www.cyderes.com 🔍 0 CVE(s) referenced

A sophisticated, large-scale malware campaign is covertly infecting hundreds of thousands of global victims by disguising a dual-stage, modular attack chain—featuring the novel RenEngine Loader and an advanced HijackLoader variant—inside cracked game installers, enabling persistent credential theft while evading detection through creative abuse of legitimate gaming frameworks and extensive anti-analysis techniques.

vendor

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle