Gaming Engines: An Undetected Playground for Malware Loaders
Essential information
- Published
- 27/11/2024 15:11
- Modified
- 29/11/2024 11:03
- Tags
- 2024-11-27 cross-platform gaming gdscript godloader godot engine malware loader redline stargazers ghost network undetected technique xmrig
- Related entities
- 14 techniques (mitre), 3 malware
Description
Check Point Research uncovered a new technique exploiting the Godot Engine to execute malicious GDScript code, remaining undetected by most antivirus tools. The technique has been used since June 2024, potentially infecting over 17,000 machines. A loader called GodLoader employs this method and is distributed via the Stargazers Ghost Network on GitHub. The technique allows cross-platform targeting of Windows, macOS, Linux, Android, and iOS devices. Researchers demonstrated successful payload drops on Linux and MacOS. This approach could potentially target over 1.2 million users of Godot-developed games through malicious mods or downloadable content.