
Downloading pirated video games or software can be a direct gateway to cyber attacks. Cyber security company Kaspersky has warned about the distribution of the RenEngine bootloader malware that hides in modified versions of games and illegal programs.
According to the company, this threat has been circulating online for about a year and has affected users in several countries, including Spain, Brazil, Russia, Turkey and Germany. The firm’s threat research team first discovered this malicious activity in March 2025.
Since then, the company’s security systems have blocked numerous infection attempts related to this software. Technical analysis published by experts shows that RenEngine works as a loaderthat is, a a tool designed to install other threats on the victim’s system, undetected by the user.

Initially, researchers believed that the malware spread exclusively through pirated video games. However, subsequent research has shown that cybercriminals have expanded their strategy.
To achieve this, created a network of fake sites designed to illegally download various popular programs. Even modified versions of CorelDRAW graphic design software have been found among them, greatly increasing the potential number of victims.
The attack method is based on manipulated versions of games developed on the Ren’Py enginea tool widely used to create visual novels. When the user downloads and installs the infected file, the process looks completely normal. The installer displays a legitimate boot screen that simulates the installation process.

However, when the progress bar reaches 100%, a true infection occurs. During this time, malicious scripts are executed in the background, which remain invisible to the user. These scripts are designed to evade security scanning systems and start downloading other computer threats to your computer.
The second phase of the attack It is produced using a tool known as HijackLoader that allows you to inject new malicious payloads into your system. In this way, attackers can install different types of malware depending on their goals, such as programs to steal passwords, collect system information, or remotely control the device.
As Pavel Sinenko, a leading malware analyst at the Kaspersky research group, explained, criminals have begun to apply the same technique to pirated software. This means that The risk is no longer limited to video games, but can also affect those who download illegal software for work or creative purposes.

Experts note that the distribution pattern revealed does not necessarily indicate campaigns directed against specific targets. Instead, the analysis shows that it is opportunistic cyber attacksdesigned to infect as many users as possible who are looking for free downloads from unofficial sites.
This type of strategy takes advantage of a common online behavior: searching for free or cracked versions of paid software. Cybercriminals use this requirement to hide malicious files in seemingly legitimate installers, making it difficult for victims to detect the risk before executing the file.
Given this situation, Experts recommend being very careful when downloading software from the Internet. The main protection measure is to use only official platforms or recognized stores to get software and video games.

It is also advisable to install a reliable security solution that can detect threats before they are executed, as well as keep the operating system and all programs installed on the computer up-to-date. Updates usually include security patches that fix vulnerabilities exploited by attackers.
finally Experts recommend not to trust any offers that promise free full versions of paid programs on unknown pages. While these downloads may seem like a quick way to save money, in many cases they expose the user to computer infections, data theft, and other digital security risks.

