Securelist
RenEngine Loader Malware Infects Over 400,000 Devices via Pirated Games
First seen 11 Feb 2026, 19:30 UTC
•



+1
•86% similarity
•38.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
In February 2026, researchers discovered a malware strain known as RenEngine Loader that has infected over 400,000 devices through pirated PC games. This malware, hidden in modified game installers for popular franchises like Assassin's Creed and FIFA, spreads the ACR Stealer and has been active since April 2025, primarily targeting users in India, the U.S., and Brazil.
ThreatCluster AI
How this analysis works
Timeline
2025-04-01
RenEngine Loader attack campaign began
2026-02-07
Cyderes reports over 400,000 infections from RenEngine Loader
2026-02-10
GBHackers News details global impact of RenEngine Loader
2026-02-11
Howler Cell announces discovery of RenEngine malware