Hackers are spreading the new GodLoader malware by exploiting the capabilities of the widely used Godot game engine to evade detection and infect over 17,000 systems in just three months.
See also: macOS Malware Banshee Stealer Source Code Leaked

As Check Point Research while investigating the attacks, threat actors can use this malware loader to target players across all major platforms, including Windows, macOS, Linux, Android, and iOS.
It is also used to leverage the flexibility of Godot and the capabilities of the GDScript to execute arbitrary code and bypass detection systems by using .pck , which package game assets, to embed malicious scripts.
Once loaded, the maliciously crafted files trigger malicious code on victims’ devices, allowing attackers to steal credentials or download additional payloads, including the XMRig crypto miner. The configuration of this miner malware was hosted in a private Pastebin uploaded in May, which was viewed 206,913 times throughout the campaign.
The attackers delivered the GodLoader malware via the Stargazers Ghost Network , a Distribution-as-a-Service (DaaS) malware that disguises its activities using seemingly legitimate GitHub repositories .
See also: Hackers target Asia and Europe with HATVIBE & CHERRYSPY malware – Greece also targeted
Between September and October 2024, they used over 200 repositories controlled by more than 225 Stargazer Ghost accounts to deploy the malware on target systems, exploiting potential victims' trust in open source platforms and seemingly legitimate software repositories.

Throughout the campaign, Check Point identified four separate waves of attacks against developers and gamers between September 12 and October 3, prompting them to download infected tools and games.
While security researchers only discovered samples of GodLoader targeting Windows systems, they also developed a PoC of GDScript that shows how easily it can be adapted to attack Linux and macOS systems.
Stargazer Goblin, the threat actor behind the Stargazers Ghost Network DaaS platform used in these attacks, was first observed by Check Point promoting this malware on the dark web in June 2023. However, it has likely been active since at least August 2022. earning over $100,000 since this service was launched.
See also: New version of NodeStealer malware targets Facebook Ads Manager accounts
Malware is a form of software designed to cause damage or gain unauthorized access to computer systems. The most common types of malicious software include viruses, worms, Trojans, ransomware, and spyware. These programs are often installed by targeting security vulnerabilities or by tricking users, such as with suspicious links or infected files. Protection against malware requires using up-to-date antivirus programs, adhering to security best practices, and being careful when surfing the Internet.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
