TechForge

December 9, 2024

Imagine your computer as a shared playground. Different players use it for a variety of activities, including work and gaming. What if someone sneaks in and plants traps all over the playground, turning it into a danger zone?

This is precisely what is happening with GodLoader, a new malware campaign that has exploited over 17,000 systems since June 2024 by misusing the popular Godot Engine, a tool trusted by both developers and gamers alike.

The Godot Engine is a versatile open-source tool for creating cross-platform games, and is at the heart of this latest security scare. While Godot’s flexibility has empowered countless developers, it has also attracted the attention of cybercriminals. Attackers have discovered a way to exploit it, running malicious code that goes undetected by most conventional antivirus software.

According to security firm, Check Point, “The technique remains undetected by almost all antivirus engines in VirusTotal.” This poses a potential risk for anyone whose computer is used for both gaming and professional tasks.

How cybercriminals are exploiting Godot Engine

The malware campaign is built on GitHub, a platform relied upon by developers and tech enthusiasts. According to The Hacker News, cybercriminals are abusing this trust by creating hundreds of fake GitHub repositories and accounts, making their malware appear legitimate. These repositories host Godot Engine executables, which act as delivery mechanisms for malware like RedLine Stealer and XMRig, a cryptocurrency miner.

The sophistication of the attacks is worth noting. Between September and October 2024, several waves of malware were observed. They used Godot pack files (.PCK) to deliver the GodLoader malware, which in turn downloaded final-stage payloads from Bitbucket repositories.

The malware’s ability to evade detection is particularly dangerous. It can bypass sandbox environments designed to analyse threats and disable Microsoft Defender Antivirus by adding the entire C:\ drive to the exclusions list.

Although most attacks have targeted Windows devices so far, experts warn that adapting GodLoader to macOS or Linux would be relatively simple. Its cross-platform design broadens its reach, making it an even more potent threat.

Why work-from-home workers should be alarmed

For work-from-home employees, the overlap between personal and professional device use poses a significant vulnerability. If you share your home computer with gamers, the threats increase significantly.

Cybercriminals have been known to tamper with legitimate Godot-built games by obtaining encryption keys. Downloading a seemingly harmless game from an untrusted source could inadvertently deliver malware to your system.

Unlike targeted attacks on corporate networks, GodLoader doesn’t differentiate between gaming files and sensitive work documents. This makes work-from-home setups very appealing to attackers. A single compromised device may give away login credentials, confidential work files, and even access to a corporate network, putting entire organisations at risk.

Cybercriminals are increasingly targeting well-known platforms and brands, capitalising on the goodwill and reputation of open-source tools. Godot Engine, popular among developers for its simplicity and versatility, has in this case become a conduit for malicious operations.

Trust and security in the open-source world

The malware campaign emphasises the importance of exercising caution when using unknown download sources. Eli Smadja, security research group manager at Check Point Software Technologies, explains: “The Godot Engine’s flexibility has made it a target for cybercriminals, enabling stealthy, cross-platform malware like GodLoader to spread rapidly by exploiting trust in open-source platforms.” With over 1.2 million users of Godot-developed games, the potential impact of this campaign is far-reaching.

The Godot Security Team has responded, reminding users that no programming language is immune to abuse. They caution users to only download software from trusted sources and to verify that executables are signed by reputable parties. They also recommend avoiding ‘cracked software,’ which frequently harbours hidden threats.

To improve security even further, developers are encouraged to adopt stronger encryption practices, such as asymmetric-key algorithms, to safeguard games and associated systems from tampering.

How to stay protected

Protecting against threats like GodLoader necessitates preemptive measures. It is critical to always download software from official and verified sources. Avoid cracked or pirated games, as they are frequently used as vehicles for malware. Work-from-home users should consider using separate devices for professional and personal use to minimise overlap and vulnerabilities.

Keeping antivirus software updated is another critical step. Advanced security solutions capable of detecting unconventional malware techniques can provide additional defences.

Staying informed about emerging threats and practising good cybersecurity hygiene is also important to protecting both personal and professional data.

Want to learn more about cybersecurity and the cloud from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is co-located with other leading events including Digital Transformation Week, IoT Tech Expo, Blockchain Expo, and AI & Big Data Expo.

Explore other upcoming enterprise technology events and webinars powered by TechForge here.

Author

  • As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

    View all posts

About the Author

Muhammad Zulhusni

As a tech journalist, Zul focuses on topics including cloud computing, cybersecurity, and disruptive technology in the enterprise industry. He has expertise in moderating webinars and presenting content on video, in addition to having a background in networking technology.

Related

August 11, 2026

August 10, 2026

August 5, 2026

July 30, 2026

Join our Community

Subscribe now to get all our premium content and latest tech news delivered straight to your inbox

Popular

12345 view(s)
11326 view(s)
7643 view(s)
6152 view(s)

Subscribe

All our premium content and latest tech news delivered straight to your inbox

This field is for validation purposes and should be left unchanged.
Name(Required)