Cybercriminals are using the Godot Engine to spread malware undetected by most antivirus solutions, according to Check Point Research. The malware, dubbed “GodLoader,” uses Godot’s scripting language, GDScript, to deliver malicious payloads. It has infected over 17,000 devices since June 2024. The distribution is linked to the Stargazers Ghost Network, a GitHub-based “Malware-as-a-Service” operation. The malware can target devices running multiple operating systems, reflecting a growing trend in cybercrime innovation.

MuddyWater Using New Malware Toolkit to Deliver Phoenix Backdoor Malware to International Organizations
The Advanced Persistent Threat group MuddyWater, widely recognized as an Iran-linked espionage actor, has orchestrated a sophisticated phishing campaign targeting more than 100 government entities
