Criminals are using fake game downloads to slip a sophisticated information stealer onto Windows computers.
The campaign hides behind supposed games, mods, cracks, and other software, exploiting the trust and urgency around free or hard-to-find downloads.
A downloaded archive can appear harmless and may even display a loading or installation screen.
Behind that screen, a hidden chain of programs prepares Amatera Stealer, malware built to collect passwords, browser data, cryptocurrency-wallet information, messaging-app data, and local files.
Malwarebytes said in a report shared with Cyber Security News (CSN) that the activity uses RenPy Loader, a multi-stage framework that turns a legitimate game-development engine into a delivery vehicle.
Researchers found the campaign on malicious download sites, game portals, and file-sharing services, where redirects can lead victims through several lookalike pages.
The risk goes beyond a lost game account. Stolen browser credentials and session data can open a route into email, social media, financial services, and business systems, while wallet theft can result in immediate and irreversible losses.
Hackers Turn Fake Games Into Multi-Stage Infostealers
The infection starts when a victim opens Setup.exe from a downloaded archive.
RenPy Loader abuses RenPy, an open-source engine commonly used for visual novels and interactive fiction, to conceal malicious Python-enabled content inside a package that looks related to gaming.
The first stage checks for analysis environments, decrypts a ZIP archive, and writes its contents to a random temporary folder.
It then removes Windows Mark of the Web protection from extracted content and uses forfiles.exe to launch a batch file, making a routine-looking installer the entry point for a much larger operation.
.webp)
That batch file invokes MSBuild, a legitimate Windows build component, to load a tampered .NET library called Nancy. The library decrypts data, alters network settings, performs anti-forensics activity, and launches another hidden component.
This approach resembles MsBuild abuse in malware, where trusted Windows utilities can be repurposed to mask malicious execution.
The next downloader, GollopDevest.dll, uses EtherHiding to retrieve its command server from blockchain data rather than storing the address directly in the malware.
.webp)
That complicates takedowns and detection, a tactic also seen in blockchain-based EtherHiding malware technique. It then pulls down additional components that finally decrypt and run Amatera Stealer.
Credentials and Wallets at Risk
Amatera targets information that can be quickly converted into access or money. Browser passwords, cookies, and other session data may let an attacker enter services without repeatedly requesting credentials, while cryptocurrency wallets, extensions, messaging apps, and files expand the possible damage to individuals and organizations.
The payload is not fixed across every RenPy Loader operation. Researchers have previously observed the loader distributing HijackLoader and Lumma Stealer, suggesting operators can change the final malware to suit a campaign.
Readers tracking earlier Amatera Stealer activity or a malicious game cheat package campaign should treat unsolicited gaming downloads as a broader malware-delivery risk. Fake cheats, cracks, and unofficial mods can all provide an effective lure for malware operators.
.webp)
The practical defense is straightforward: download games and software only from official sites, trusted stores, or established platforms.
Avoid cracked releases and unofficial mods, inspect archives before opening executable files, and leave any download path that bounces through unfamiliar sites or file-sharing pages.
Users should also keep Windows, browsers, and security software updated, because a polished installer or familiar hosting service is not proof that a download is safe.
Organizations can reduce exposure by restricting unapproved software, monitoring unusual MSBuild activity, and resetting exposed passwords promptly.
Security teams should review alerts for unexpected Setup.exe, MSBuild, and forfiles.exe activity after game installations, then preserve suspicious archives for analysis.
Investigation can identify accounts, isolate devices, and prevent stolen sessions from being reused against services.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | downpro.net | Fake download website |
| Domain | macisofile.sbs | Fake download website |
| Domain | visitmama.blog | Fake download website |
| Domain | visitmama.guru | Fake download website |
| Domain | getgamerfree.com | Fake download website |
| Domain | fullgames.digital | Fake download website |
| Domain | flingbase.net | Fake download website |
| Domain | citronemu.com | Fake download website |
| Domain | filemodo.xyz | Distribution infrastructure |
| Domain | storage06x.cfd | Distribution infrastructure |
| Domain | p03sil.cyou | Distribution infrastructure |
| Domain | wimsedas.xyz | Distribution infrastructure |
| Domain | againstmor.store | Distribution infrastructure |
| Domain | host03q.cfd | Distribution infrastructure |
| Domain | cloud01y.cfd | Distribution infrastructure |
| Domain | storage11x.cfd | Distribution infrastructure |
| Domain | storage04x.cfd | Distribution infrastructure |
| Domain | host82p.cfd | Distribution infrastructure |
| Domain | cloud05y.cfd | Distribution infrastructure |
| Domain | analyticstrack-pzh.click | Tracking website |
| Domain | login.orbitalframework.cc | Amatera Stealer C2 |
| IP address | 144.124.251.171 | Used to obtain additional payloads |
| IP address | 195.63.140.33 | Used to obtain additional payloads |
| IP address | 78.40.196.252 | Used to obtain additional payloads |
| MD5 | 29203ca123d51b1b33505a0813d360df | First-stage loader, trojanized DLL |
| MD5 | 810F257542018BE0FC62AF542D13D012 | GollopDevest DLL downloader |
| MD5 | 681DB529E402467A4B0567C82A350FC0 | PavinWride DLL anti-analysis component |
| MD5 | 2E116632248A7E1F8AA6BCA92D9C1C90 | GollopDevest DLL loader |
| MD5 | F8453EFE408CE25B9484F872797E3D63 | Final payload |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
! ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposuremalware to businesses an

