Malware has been discovered that uses the Godot game engine as a platform for execution.

Checkpoint has reported the discovery of malware called GodLoader, which is written in GDScript and utilizes the open-source game engine Godot for its execution (the Godot engine is used as a launch platform). Writing code in GDScript allowed the distribution of malicious programs among computer gamers under the guise of mods and game resources in pck format, processed by the Godot engine. The use of GDScript also enabled it to be independent of the operating system installed on the user's device (Windows, macOS, Linux, Android, and iOS).

Since running programs in GDScript requires the Godot engine, the primary target of the attack was users of games on this engine. The earliest instances of the new malware date back to June 29. More than 17,000 systems infected with GodLoader have been documented. Typically, victims of the attack downloaded unverified pck archives with integrated GodLoader from third-party resources and counterfeit repositories on GitHub. After executing the script contained in the archive written in GDScript, GodLoader would load and execute additional malicious components that performed actions such as cryptocurrency mining and transferring stored passwords and access keys from the user's system.

Malware has been discovered that uses the Godot game engine as a platform for execution.


Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster