Alpha Cyber

GodLoader Malware: How Attackers Exploit the Godot Engine Threat Insights

Cybercriminals are exploiting the Godot Engine in a new wave of attacks using the GodLoader malware, infecting over 17,000 systems in just three months.

Alpha Cyber Research1 min readupdated 1 Apr 2026
GodLoader

Cybercriminals are exploiting the Godot Engine in a new wave of attacks using the GodLoader malware, infecting over 17,000 systems in just three months. By leveraging Godot’s open-source flexibility and its GDScript scripting language, attackers craft malicious .pck files that, when loaded with the Godot runtime, execute harmful code on victims’ devices. This approach enables GodLoader to evade most antivirus detections, as confirmed by VirusTotal scans.

How GodLoader Works

  • Malicious GDScript: Attackers embed harmful scripts in .pck files, which are then distributed via platforms like GitHub and Bitbucket.

  • Multi-Platform Impact: The malware targets Windows, macOS, Linux, Android, and iOS, broadening the attack surface.

  • Payload Delivery: Once executed, GodLoader can steal credentials, deploy additional malware (such as the XMRig crypto miner), and maintain persistence on infected systems.

  • Distribution-as-a-Service: Threat actors use a network of fake repositories and accounts to mask their activities and spread the loader to unsuspecting users.

Why This Matters for Your Organization

  • Stealthy Attacks: GodLoader’s use of game development tools allows it to bypass many traditional security controls.

  • Widespread Reach: Its cross-platform design means both business and personal devices are at risk.

  • Rapid Infection: Over 17,000 systems compromised in a few months demonstrates the campaign’s scale and effectiveness.

Protect your business by blocking known Indicators of Compromise (IoCs) and monitoring for suspicious Godot-related activity.

GodLoader IoCs to Block

TypeIndicatorDescription
Domainraw.githubusercontent.comPayload hosting (GitHub)
Domainbitbucket.orgPayload hosting (Bitbucket)
Domainpastebin.com/private/xyz123XMRig miner config (example)
IP Address185.199.108.133GitHub infrastructure
IP Address104.21.234.21Pastebin infrastructure
File Hash (SHA256)3f2e1c7c4e5b1e5d2d6e4e1e9a5c2b1d9e7d8c8f7b6a5e4d3c2b1a9e8f7d6c5bGodLoader loader sample
File Extension.pckSuspicious Godot asset package
File Namegodot.exe + suspicious .pck fileLoader pair

Note: These IoCs are representative. For real-time, campaign-specific IoCs, contact our threat intelligence team.

Stay ahead of emerging threats.


Let our experts help you monitor, detect, and block GodLoader and similar malware targeting your organization. Contact us today for a tailored endpoint security and threat intelligence solution.

Keep reading

Related research

Daxin Rootkit
Threat ReportsTLP:AMBER

Daxin Returns: A 13-Year-Old China-Linked Rootkit That Never Called Home

Symantec found the Daxin kernel rootkit still operational on a Taiwan manufacturing subsidiary in 2026, alongside a previously undocumented backdoor, Stupig, that runs SYSTEM commands from the Windows logon screen before anyone signs in.

6 min readAPT

Contact

Talk to someone who has seen this before.

You speak directly to the people doing the work, wherever in the world you operate.

Or email [email protected]