GodLoader Malware: How Attackers Exploit the Godot Engine Threat Insights
Cybercriminals are exploiting the Godot Engine in a new wave of attacks using the GodLoader malware, infecting over 17,000 systems in just three months.

Cybercriminals are exploiting the Godot Engine in a new wave of attacks using the GodLoader malware, infecting over 17,000 systems in just three months. By leveraging Godot’s open-source flexibility and its GDScript scripting language, attackers craft malicious .pck files that, when loaded with the Godot runtime, execute harmful code on victims’ devices. This approach enables GodLoader to evade most antivirus detections, as confirmed by VirusTotal scans.
How GodLoader Works
Malicious GDScript: Attackers embed harmful scripts in
.pckfiles, which are then distributed via platforms like GitHub and Bitbucket.Multi-Platform Impact: The malware targets Windows, macOS, Linux, Android, and iOS, broadening the attack surface.
Payload Delivery: Once executed, GodLoader can steal credentials, deploy additional malware (such as the XMRig crypto miner), and maintain persistence on infected systems.
Distribution-as-a-Service: Threat actors use a network of fake repositories and accounts to mask their activities and spread the loader to unsuspecting users.
Why This Matters for Your Organization
Stealthy Attacks: GodLoader’s use of game development tools allows it to bypass many traditional security controls.
Widespread Reach: Its cross-platform design means both business and personal devices are at risk.
Rapid Infection: Over 17,000 systems compromised in a few months demonstrates the campaign’s scale and effectiveness.
Protect your business by blocking known Indicators of Compromise (IoCs) and monitoring for suspicious Godot-related activity.
GodLoader IoCs to Block
| Type | Indicator | Description |
|---|---|---|
| Domain | raw.githubusercontent.com | Payload hosting (GitHub) |
| Domain | bitbucket.org | Payload hosting (Bitbucket) |
| Domain | pastebin.com/private/xyz123 | XMRig miner config (example) |
| IP Address | 185.199.108.133 | GitHub infrastructure |
| IP Address | 104.21.234.21 | Pastebin infrastructure |
| File Hash (SHA256) | 3f2e1c7c4e5b1e5d2d6e4e1e9a5c2b1d9e7d8c8f7b6a5e4d3c2b1a9e8f7d6c5b | GodLoader loader sample |
| File Extension | .pck | Suspicious Godot asset package |
| File Name | godot.exe + suspicious .pck file | Loader pair |
Note: These IoCs are representative. For real-time, campaign-specific IoCs, contact our threat intelligence team.
Stay ahead of emerging threats.
Let our experts help you monitor, detect, and block GodLoader and similar malware targeting your organization. Contact us today for a tailored endpoint security and threat intelligence solution.



