Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
loader-delivery-mechanismcredential-stealer-activityinitial-access-methodremote-access-implant

Malware Campaigns Using Fake Installers and Multi-Stage Loaders to Steal Credentials and Enable Remote Control

Updated 3mo agoFirst seen Feb 6, 20263 sources

Multiple active malware campaigns are using trojanized installers and social engineering—rather than software vulnerabilities—to gain initial access and then deploy credential theft or remote-control capabilities. Intel 471 reported a new Android banking trojan dubbed FvncBot targeting Polish mobile banking users by impersonating an mBank “security” app; the dropper prompts installation of an additional “Play” component and then abuses Android Accessibility Services for persistence and control, enabling keylogging, screen capture, and hidden VNC-style remote interaction to facilitate fraudulent transactions.

Separately, Cyderes described an ongoing, large-scale piracy-channel campaign where cracked game installers hide behind a legitimate-looking Ren’Py launcher tracked as RenEngine, which decrypts and launches subsequent stages and introduces HijackLoader via techniques including DLL side-loading and module stomping; observed final payloads include ACR Stealer (and in some cases Vidar) to exfiltrate browser credentials, cookies, and crypto wallet data. Cybereason detailed a different installer-themed operation in Chinese-speaking communities delivering ValleyRat/Winos 4.0 attributed to Silver Fox APT, notable for using the rare “PoolParty Variant 7” process injection (abusing Windows I/O completion ports and ZwSetIoCompletion() after duplicating a handle from Explorer.exe) plus a strengthened watchdog mechanism via injection into Explorer.exe and UserAccountBroker.exe to maintain persistence.

Share:
Malware Campaigns Using Fake Installers and Multi-Stage Loaders to Steal Credentials and Enable Remote Control
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 6, 20265mo ago

RenEngine loader multi-stage execution chain publicly reported

A report published on February 6, 2026 described the RenEngine loader as using a stealthy multi-stage execution chain to bypass security controls. No further incident timing or victim details were provided in the reference.

Intel471 discloses technical details of the new FvncBot malware

Intel471 reported that FvncBot appears to have an original codebase rather than being derived from leaked banking trojan source code, suggesting a new developer group. The disclosure detailed its use of Accessibility Services, hidden VNC, keystroke logging, screen capture, WebSocket-based command and control, and data exfiltration capabilities.

Researchers reveal ValleyRat's use of PoolParty Variant 7 injection

The Silver Fox-linked ValleyRat campaign was found to use the rare PoolParty Variant 7 process-injection technique, abusing Windows I/O Completion Ports and Explorer.exe handles to run code inside trusted processes. Researchers also noted a watchdog persistence mechanism and attempts to disrupt Qihoo 360 security products.

Cybereason reports Silver Fox campaign delivering ValleyRat via trojanized installers

Cybereason Security Services reported a campaign targeting Chinese-speaking users with trojanized software installers, including a fake LINE installer that delivered the ValleyRat (Winos 4.0) remote access trojan. The activity was assessed as linked to the Silver Fox APT.

Nov 25, 20257mo ago

FvncBot banking trojan campaign observed targeting Polish Android users

On November 25, 2025, researchers observed a malicious Android app masquerading as an mBank security tool and targeting mobile banking customers in Poland. The app served as a loader for the newly identified FvncBot trojan and used social engineering to get victims to install an additional component for persistence and evasion.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

15 LINKEDOpen in app
Threat actors
1 linked
Affected products
4 linked
AndroidTodeskWindowsAnydesk
Organizations
7 linked
Intel 471mBankTodeskQihoo 360CybereasonAnyDesk Software GmbHLINE Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Malware Campaigns Using Fake Installers and Multi-Stage Loaders to Steal Credentials and Enable Remote Control | Mallory