Hackers are more and more abusing decentralized infrastructure and bonafide growth frameworks to evade detection, with a newly noticed marketing campaign leveraging Ethereum sensible contracts to hide command-and-control (C2) endpoints for the Amatera Stealer infostealer.
These lures are propagated عبر malicious web sites, file-sharing platforms equivalent to Google Drive, MEGA, GoFile, and Wormhole, and spoofed obtain portals designed to imitate official distribution channels.
The an infection chain begins with a trojanized archive containing a Setup.exe binary. Whereas victims are introduced with a benign-looking set up interface, malicious processes execute silently within the background.
The loader abuses the official Ren’Py engine generally used for visible novels and interactive fiction to embed and execute malicious Python code, rising the plausibility of the payload.
This marketing campaign displays a broader development beforehand noticed with frameworks like Bun and Deno, the place attackers weaponize trusted growth ecosystems to bypass safety controls and cut back suspicion.
Comparable strategies had been documented in earlier campaigns distributing NwHStealer through Bun (https://www.malwarebytes.com/weblog/threat-intel/2026/05/attackers-adopt-javascript-runtime-bun-to-spread-nwhstealer).
Deno-based RATs (https://www.malwarebytes.com/weblog/threat-intel/2026/05/fake-software-on-github-and-sourceforge-distribute-deno-rat).
As soon as executed, RenPy Loader initiates a multi-stage an infection chain involving obfuscated payload supply and protection evasion.
Malwarebytes Researchers have recognized a number of ongoing campaigns distributing a malware loader generally known as RenPy Loader (additionally tracked as RenEngine Loader) by way of pretend downloads of video games, cracked software program, and mods.
Amatera Stealer C2 Servers
The primary-stage loader extracts encrypted elements from embedded assets, together with XOR-protected configuration information and ZIP archives.


It performs sandbox detection checks and removes the Mark-of-the-Net flag through alternate knowledge streams to bypass Home windows SmartScreen protections.
The loader then executes a BAT script by way of forfiles.exe, which launches a hidden conhost.exe occasion and invokes MSBuild.exe with a malicious undertaking file (Nancy.csproj).
This system allows execution of inline .NET payloads utilizing MSBuild property features, a identified living-off-the-land binary (LOLBIN) abuse vector.
A trojanized model of the Nancy .NET framework is subsequently reconstructed and executed in reminiscence. The payload employs heavy obfuscation, together with customized bytecode interpretation, multi-layer XOR encryption, API hashing, and oblique operate decision.

It additionally modifies system community configurations, disables TLS certificates validation, and performs anti-forensics operations.
Essentially the most notable side of this marketing campaign is using EtherHiding a way that leverages blockchain knowledge to retailer or retrieve malicious infrastructure particulars.
As a substitute of embedding the C2 deal with straight within the malware, the loader points an Ethereum JSON-RPC request to a public blockchain endpoint (bsc-dataseed.binance.org), querying a wise contract to retrieve encrypted C2 data.
This considerably complicates detection and takedown efforts, as blockchain knowledge is immutable and decentralized.
The retrieved C2 endpoint is then used to obtain extra payloads, together with a number of obfuscated .NET and native DLLs equivalent to PavinWide, GollopDevest, and LanoseThrip.

These elements in the end decrypt and execute the ultimate payload: Amatera Stealer.
Amatera is a data-harvesting malware designed to extract delicate data from contaminated methods, together with browser-stored credentials, cryptocurrency pockets knowledge, messaging software content material, browser extensions, and native information.
Stolen session tokens and credentials can allow account takeover assaults throughout a number of platforms.
Notably, RenPy Loader has additionally been noticed delivering various payloads equivalent to Lumma Stealer and HijackLoader, indicating a versatile malware-as-a-service (MaaS) distribution mannequin.
The reuse of EtherHiding infrastructure throughout campaigns, together with ClickFix exercise, additional helps this evaluation.
The mix of blockchain-based C2 concealment, official instrument abuse, and multi-stage in-memory execution highlights a rising shift towards resilient, stealth-focused malware supply.
As attackers proceed to mix decentralized applied sciences with trusted software program frameworks, conventional detection mechanisms face rising challenges in figuring out and disrupting these campaigns.
IOCs
| Indicator | Sort |
|---|---|
| downpro[.]web | Pretend obtain web site |
| macisofile[.]sbs | Pretend obtain web site |
| visitmama[.]weblog | Pretend obtain web site |
| visitmama[.]guru | Pretend obtain web site |
| getgamerfree[.]com | Pretend obtain web site |
| fullgames[.]digital | Pretend obtain web site |
| flingbase[.]web | Pretend obtain web site |
| citronemu[.]com | Pretend obtain web site |
| filemodo[.]xyz | Distribution infrastructure |
| storage06x[.]cfd | Distribution infrastructure |
| p03sil[.]cyou | Distribution infrastructure |
| wimsedas[.]xyz | Distribution infrastructure |
| againstmor[.]retailer | Distribution infrastructure |
| host03q[.]cfd | Distribution infrastructure |
| cloud01y[.]cfd | Distribution infrastructure |
| storage11x[.]cfd | Distribution infrastructure |
| storage04x[.]cfd | Distribution infrastructure |
| host82p[.]cfd | Distribution infrastructure |
| cloud05y[.]cfd | Distribution infrastructure |
| analyticstrack-pzh[.]click on | Monitoring web site |
| login.orbitalframework[.]cc | C2 (Amatera Stealer) |
| 144.124.251[.]171 | Malicious IP (Payload supply) |
| 195.63.140[.]33 | Malicious IP (Payload supply) |
| 78.40.196[.]252 | Malicious IP (Payload supply) |
Word: IP addresses and domains are deliberately defanged (e.g., [.]) to stop unintentional decision or hyperlinking. Re-fang solely inside managed menace intelligence platforms equivalent to MISP, VirusTotal, or your SIEM.
What Options Ought to AI SOC Have in 2026? A Full Guidelines : Obtain the AI SOC Options Guidelines









