Fake games spread stealers via RenPy Loader and EtherHiding
Attackers are distributing malicious software disguised as legitimate video games. By using the Ren'Py game engine, they hide harmful code that can steal sensitive information from users' computers.

English Brief
Attackers are distributing malicious software disguised as legitimate video games. By using the Ren'Py game engine, they hide harmful code that can steal sensitive information from users' computers.
الموجز العربي
ألعاب مزيفة تنشر برمجيات سرقة البيانات عبر RenPy Loader وتقنية EtherHiding
يقوم المهاجمون بتوزيع برمجيات خبيثة متخفية في هيئة ألعاب فيديو حقيقية. من خلال استخدام محرك الألعاب Ren'Py، يقومون بإخفاء أكواد ضارة يمكنها سرقة معلومات حساسة من أجهزة الكمبيوتر الخاصة بالمستخدمين.
- 1Identify and remove suspicious game files; # 2. Restrict MSBuild execution for non-developer groups via GPO; # 3. Block access to known malicious blockchain-hosted domains if identified in logs; # 4. Perform a full endpoint scan using updated antivirus definitions; # 5. Reset credentials for any accounts accessed on compromised machines.
English Advisory
// Intelligence Summary
Threat actors are exploiting the Ren'Py visual novel engine to facilitate the delivery of the 'Amatera Stealer'. The campaign leverages a multi-stage infection chain involving MSBuild and the 'EtherHiding' technique to conceal malicious payloads within the blockchain.
التقرير العربي
// ملخص استخباراتي
يستغل المهاجمون محرك الروايات المرئية Ren'Py لتسهيل نشر برنامج 'Amatera Stealer'. تستخدم الحملة سلسلة عدوى متعددة المراحل تتضمن أداة MSBuild وتقنية 'EtherHiding' لإخفاء الحمولات الضارة داخل تقنية البلوكشين.
// Technical Context
The malware delivery mechanism uses a legitimate game development framework to execute a loader. This loader fetches secondary payloads while bypassing traditional detection by utilizing MSBuild. The 'EtherHiding' methodology involves storing parts of the malicious script on public blockchain infrastructure, which acts as a decentralized and persistent command-and-control (C2) mechanism.
// السياق الفني
تستخدم آلية تسليم البرمجيات الخبيثة إطار عمل تطوير ألعاب مشروع لتنفيذ محمل برمجيات. يقوم هذا المحمل بجلب حمولات ثانوية مع تجاوز أنظمة الكشف التقليدية عن طريق استخدام أداة MSBuild. تتضمن منهجية 'EtherHiding' تخزين أجزاء من النص البرمجي الضار على بنية تحتية عامة للبلوكشين، والتي تعمل كآلية لا مركزية ومستمرة للتحكم والقيادة (C2).
// Exposure Notes
Users downloading unauthorized or pirated game files from untrusted sources are at high risk. The malware's reliance on legitimate build tools and blockchain-based hosting makes detection via signature-based systems challenging.
// ملاحظات التعرض
المستخدمون الذين يقومون بتنزيل ملفات ألعاب غير مصرح بها أو مقرصنة من مصادر غير موثوقة معرضون لخطر كبير. اعتماد البرمجيات الخبيثة على أدوات البناء المشروعة والاستضافة القائمة على البلوكشين يجعل الكشف عنها عبر الأنظمة القائمة على التوقيع أمراً صعباً.
// Defensive Priority
Organizations should block access to unauthorized gaming platforms and restrict the execution of MSBuild by non-developer entities. Endpoint Detection and Response (EDR) solutions should be configured to monitor for suspicious child processes spawned by game-related executables.
// أولوية الدفاع
يجب على المؤسسات منع الوصول إلى منصات الألعاب غير المصرح بها وتقييد تنفيذ MSBuild للمستخدمين غير المطورين. يجب تكوين حلول الكشف والاستجابة لنقاط النهاية (EDR) لمراقبة العمليات الفرعية المشبوهة التي تنبثق عن الملفات التنفيذية المتعلقة بالألعاب.
Mitigation Checklist
- 1Identify and remove suspicious game files; # 2. Restrict MSBuild execution for non-developer groups via GPO; # 3. Block access to known malicious blockchain-hosted domains if identified in logs; # 4. Perform a full endpoint scan using updated antivirus definitions; # 5. Reset credentials for any accounts accessed on compromised machines.
قائمة إجراءات التخفيف
- 1تحديد وإزالة ملفات الألعاب المشبوهة؛ # 2. تقييد تنفيذ MSBuild لمجموعات غير المطورين عبر نهج المجموعة (GPO)؛ # 3. حظر الوصول إلى النطاقات الضارة المعروفة المستضافة على البلوكشين في حال تحديدها في السجلات؛ # 4. إجراء فحص كامل لنقطة النهاية باستخدام تعريفات مكافحة فيروسات محدثة؛ # 5. إعادة تعيين بيانات الاعتماد لأي حسابات تم الوصول إليها على الأجهزة المخترقة.
- Source: Malwarebytes Labs
# 1. Identify and remove suspicious game files; # 2. Restrict MSBuild execution for non-developer groups via GPO; # 3. Block access to known malicious blockchain-hosted domains if identified in logs; # 4. Perform a full endpoint scan using updated antivirus definitions; # 5. Reset credentials for any accounts accessed on compromised machines.