<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding-zkfrqypzs" -->

---
title: Fake games spread stealers with RenPy Loader, MSBuild...
description: Malwarebytes researchers have uncovered campaigns distributing fake games, mods, and cracked software that deploy a multi-stage malware chain using the RenPy...
canonical: https://daily.dev/posts/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding-zkfrqypzs
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding | daily.dev
og:description: Malwarebytes researchers have uncovered campaigns distributing fake games, mods, and cracked software that deploy a multi-stage malware chain using the RenPy...
og:url: https://daily.dev/posts/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding-zkfrqypzs
og:image: https://api.daily.dev/og/posts/zkFrqyPZS.png
og:image:alt: Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding

**[Security Boulevard](https://daily.dev/sources/securityboulevard)** · 9 min read · 0 upvotes · 0 comments

## Summary

Malwarebytes researchers have uncovered campaigns distributing fake games, mods, and cracked software that deploy a multi-stage malware chain using the RenPy Loader. The infection abuses the legitimate Ren'Py visual novel engine to execute malicious Python scripts, which decrypt and launch a BAT file that invokes MSBuild with a trojanized Nancy .NET DLL. This DLL uses custom bytecode and multi-key XOR decryption before loading GollopDevest, a downloader that employs EtherHiding — storing the C2 address on the Binance Smart Chain blockchain — to retrieve additional payloads. The final payload is Amatera Stealer, capable of harvesting browser credentials, crypto wallets, messaging apps, and local files. The post includes a full technical breakdown of each stage, indicators of compromise (domains, IPs, file hashes), and user safety recommendations.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securityboulevard.com/2026/07/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding>

## Questions this post answers

### What is EtherHiding and how do attackers use it to hide a command-and-control server?

EtherHiding is a technique where attackers store an encrypted C2 domain inside data on a public blockchain instead of embedding it directly in malware code. In one observed campaign, the GollopDevest downloader DLL retrieved the encrypted C2 address using an Ethereum JSON-RPC eth_call request to a Binance Smart Chain node, making the infrastructure harder to identify and takedown.

_Developers building detection tooling can track emerging techniques like blockchain-based C2 hiding through daily.dev._

### How does the RenPy Loader malware abuse the Ren'Py game engine to infect systems?

RenPy Loader hides malicious code inside Ren'Py projects by exploiting the engine's support for embedded Python scripts, disguising malware as visual novels, game mods, or cracked software. After installation it decrypts a config file and a password-protected ZIP via XOR and Base64, checks for sandboxing, strips the Mark of the Web via a Zone.Identifier alternate data stream, and launches a BAT file using forfiles.exe to continue the infection chain.

_Security teams tracking novel malware distribution vectors like game engines can follow analyses like this on daily.dev._

### How does the malicious BAT file abuse MSBuild.exe to execute the next malware stage?

The BAT file sets the environment variable MSBUILDENABLEALLPROPERTYFUNCTIONS=1 to enable extended MSBuild property functions such as AppDomain.CurrentDomain.Load, then runs MSBuild.exe against a project file named Nancy.csproj. During project evaluation, a malicious MSBuild property function hex-decodes and reflectively loads a trojanized Nancy .NET DLL as the next stage, avoiding a standalone malicious executable.

_Developers hardening CI and build pipelines against living-off-the-land abuse can stay current on techniques like this via daily.dev._

## Similar posts on daily.dev

- [The game is over: when “free” comes at too high a price. What we know about RenEngine](https://daily.dev/posts/the-game-is-over-when-free-comes-at-too-high-a-price-what-we-know-about-renengine-qp5qxbqgm) · Securelist · 0 upvotes · 0 comments
- [Fake Roblox Xeno script launcher pushes infostealer, RAT malware](https://daily.dev/posts/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware-qtwjss6dl) · BleepingComputer · 0 upvotes · 0 comments
- [New BoryptGrab Stealer Targets Windows Users via Deceptive GitHub Pages](https://daily.dev/posts/new-boryptgrab-stealer-targets-windows-users-via-deceptive-github-pages-yrwqhjw1f) · Trend Micro · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#malware](https://daily.dev/tags/malware)

[View this post on daily.dev](https://daily.dev/posts/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding-zkfrqypzs)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding","url":"https://daily.dev/posts/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding-zkfrqypzs","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding-zkfrqypzs"},"datePublished":"2026-07-20T12:00:56.067Z","dateModified":"2026-09-14T08:20:36.611Z","description":"Malwarebytes researchers have uncovered campaigns distributing fake games, mods, and cracked software that deploy a multi-stage malware chain using the RenPy...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8fe9eeb967de205fd6743e2535f16178?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8fe9eeb967de205fd6743e2535f16178?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Security Boulevard","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Security Boulevard","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/3613c832180040de8d85bb29f74395be","url":"https://daily.dev/sources/securityboulevard"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding-zkfrqypzs","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,malware","timeRequired":"PT9M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Security Boulevard","item":"https://daily.dev/sources/securityboulevard"},{"@type":"ListItem","position":3,"name":"Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding-zkfrqypzs#faq","mainEntity":[{"@type":"Question","name":"What is EtherHiding and how do attackers use it to hide a command-and-control server?","acceptedAnswer":{"@type":"Answer","text":"EtherHiding is a technique where attackers store an encrypted C2 domain inside data on a public blockchain instead of embedding it directly in malware code. In one observed campaign, the GollopDevest downloader DLL retrieved the encrypted C2 address using an Ethereum JSON-RPC eth_call request to a Binance Smart Chain node, making the infrastructure harder to identify and takedown. Developers building detection tooling can track emerging techniques like blockchain-based C2 hiding through daily.dev."}},{"@type":"Question","name":"How does the RenPy Loader malware abuse the Ren'Py game engine to infect systems?","acceptedAnswer":{"@type":"Answer","text":"RenPy Loader hides malicious code inside Ren'Py projects by exploiting the engine's support for embedded Python scripts, disguising malware as visual novels, game mods, or cracked software. After installation it decrypts a config file and a password-protected ZIP via XOR and Base64, checks for sandboxing, strips the Mark of the Web via a Zone.Identifier alternate data stream, and launches a BAT file using forfiles.exe to continue the infection chain. Security teams tracking novel malware distribution vectors like game engines can follow analyses like this on daily.dev."}},{"@type":"Question","name":"How does the malicious BAT file abuse MSBuild.exe to execute the next malware stage?","acceptedAnswer":{"@type":"Answer","text":"The BAT file sets the environment variable MSBUILDENABLEALLPROPERTYFUNCTIONS=1 to enable extended MSBuild property functions such as AppDomain.CurrentDomain.Load, then runs MSBuild.exe against a project file named Nancy.csproj. During project evaluation, a malicious MSBuild property function hex-decodes and reflectively loads a trojanized Nancy .NET DLL as the next stage, avoiding a standalone malicious executable. Developers hardening CI and build pipelines against living-off-the-land abuse can stay current on techniques like this via daily.dev."}}]}
```

