Skip to content
RenEngine Loader Malware Infects Over 400,000 Devices via Pirated Games

RenEngine Loader Malware Infects Over 400,000 Devices via Pirated Games

First seen 11 Feb 2026, 19:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 16:10 UTC

In February 2026, researchers discovered a malware strain known as RenEngine Loader that has infected over 400,000 devices through pirated PC games. This malware, hidden in modified game installers for popular franchises like Assassin's Creed and FIFA, spreads the ACR Stealer and has been active since April 2025, primarily targeting users in India, the U.S., and Brazil.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 193d ago How this analysis works

Timeline

2025-04-01
RenEngine Loader attack campaign began
2026-02-07
Cyderes reports over 400,000 infections from RenEngine Loader
2026-02-10
GBHackers News details global impact of RenEngine Loader
2026-02-11
Howler Cell announces discovery of RenEngine malware

More articles in this cluster (6)

Following this threat?

Track ACR Stealer in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed