<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/cybercriminals-exploit-godot-engine-to-distribute-cross-platform-malware-ajq5qpc3e" -->

---
title: Cybercriminals Exploit Godot Engine to Distribute...
description: Cybercriminals are using the open-source Godot Engine to distribute a cross-platform malware named GodLoader. This campaign has infected over 17,000 systems by...
canonical: https://daily.dev/posts/cybercriminals-exploit-godot-engine-to-distribute-cross-platform-malware-ajq5qpc3e
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Cybercriminals Exploit Godot Engine to Distribute Cross-Platform Malware | daily.dev
og:description: Cybercriminals are using the open-source Godot Engine to distribute a cross-platform malware named GodLoader. This campaign has infected over 17,000 systems by...
og:url: https://daily.dev/posts/cybercriminals-exploit-godot-engine-to-distribute-cross-platform-malware-ajq5qpc3e
og:image: https://api.daily.dev/og/posts/Ajq5qPc3E.png
og:image:alt: Cybercriminals Exploit Godot Engine to Distribute Cross-Platform Malware
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Cybercriminals Exploit Godot Engine to Distribute Cross-Platform Malware

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 3 upvotes · 1 comments

## Summary

Cybercriminals are using the open-source Godot Engine to distribute a cross-platform malware named GodLoader. This campaign has infected over 17,000 systems by embedding malicious scripts in .pck files, posing as legitimate software or game modifications. The malware targets primarily Windows systems but can adapt for macOS and Linux. It spreads through multiple GitHub repositories and sophisticated evasion techniques, bypassing many antivirus tools. Users are advised to download software only from trusted sources and verify authenticity to mitigate risks.

## Content

# Cybercriminals Exploit Godot Engine to Distribute Cross-Platform Malware GodLoader

Cybercriminals are exploiting the open-source Godot Engine to distribute a cross-platform malware called GodLoader. This malicious campaign has successfully infected over 17,000 systems by using the Godot engine to execute harmful GDScript code under the guise of legitimate software or game modifications. 

## Campaign Overview
The GodLoader campaign has leveraged over 200 GitHub repositories and 225 bogus accounts to distribute the malware. The sophisticated approach involves embedding scripts in .pck files, typically used by Godot, to bypass many security measures. Although GodLoader primarily targets Windows systems, it has the potential to be adapted for macOS and Linux, making it a versatile threat.

## Infection Mechanics
To execute malicious code, the malware requires the Godot runtime and a .pck file, which complicates the process, preventing simple one-click exploits. Instead, the attackers distribute software cracks or modifications that appear benign but contain the malicious payload. The infection process relies heavily on the user's trust in downloaded software, stressing the need for caution and verification of sources.

## Distribution Methods
The malware has been propagated via multiple GitHub repositories and Bitbucket accounts in four main waves. Each wave included various payloads like RedLine Stealer and XMRig miners, posing serious risks to affected systems. By leveraging reputable-looking repositories and sophisticated evasion techniques, the campaign successfully bypassed many antivirus tools.

## Security Implications
Security experts emphasize that this exploitation method is not specific to Godot but is a broader issue that can affect other programming environments such as Python or Ruby. The Godot security team and security researchers from Check Point Research underscore the importance of downloading software exclusively from trusted sources and thoroughly verifying the authenticity of executable files.

## Conclusion
The high infection rate of the GodLoader campaign can be attributed to its advanced distribution methods and the exploitation of user trust in open-source software. While Godot itself is not inherently more vulnerable than other platforms, it's crucial for users to maintain good security practices to mitigate the risks associated with such malware distribution campaigns.

## Community discussion

Top comments from developers on daily.dev.

**@dekeoma** · 0 upvotes

> @idoshamun  i just thought you should see this...
>
> AI?

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments
- [CNCF Unveils Schedule for KubeCon \+ CloudNativeCon Europe 2026](https://daily.dev/posts/cncf-unveils-schedule-for-kubecon-cloudnativecon-europe-2026-ikhcoa5cb) · CNCF · 2 upvotes · 0 comments
- [CNCF Debuts KubeCon \+ CloudNativeCon Japan 2026 Schedule](https://daily.dev/posts/cncf-debuts-kubecon-cloudnativecon-japan-2026-schedule-xp5pyudub) · CNCF · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cyber](https://daily.dev/tags/cyber), [#open-source](https://daily.dev/tags/open-source), [#game-development](https://daily.dev/tags/game-development), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/cybercriminals-exploit-godot-engine-to-distribute-cross-platform-malware-ajq5qpc3e)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Cybercriminals Exploit Godot Engine to Distribute Cross-Platform Malware","url":"https://daily.dev/posts/cybercriminals-exploit-godot-engine-to-distribute-cross-platform-malware-ajq5qpc3e","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/cybercriminals-exploit-godot-engine-to-distribute-cross-platform-malware-ajq5qpc3e"},"datePublished":"2024-11-28T10:06:13.096Z","dateModified":"2024-11-29T11:09:49.890Z","description":"Cybercriminals are using the open-source Godot Engine to distribute a cross-platform malware named GodLoader. This campaign has infected over 17,000 systems by...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0e47eaf22a0050c99c9f72260a0d249c?_a=AQAEuj9","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/0e47eaf22a0050c99c9f72260a0d249c?_a=AQAEuj9","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":1,"discussionUrl":"https://daily.dev/posts/cybercriminals-exploit-godot-engine-to-distribute-cross-platform-malware-ajq5qpc3e","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":3},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":1}],"keywords":"security,cyber,open-source,game-development,malware","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Cybercriminals Exploit Godot Engine to Distribute Cross-Platform Malware"}]}
{"@context":"https://schema.org","@type":"WebPage","@id":"https://daily.dev/posts/cybercriminals-exploit-godot-engine-to-distribute-cross-platform-malware-ajq5qpc3e","comment":[{"@type":"Comment","text":"@idoshamun  i just thought you should see this…\nAI?","datePublished":"2024-12-27T14:00:39.016Z","url":"https://daily.dev/posts/Ajq5qPc3E#c-oyfY6It99","author":{"@type":"Person","name":"Ekeoma David","url":"https://daily.dev/dekeoma","image":"https://media.daily.dev/image/upload/s--9soq7GJT--/f_auto/v1733060352/avatars/avatar_97xoE7HYGiPIKBrFwNC38"}}]}
```

