Your activity

Recently visited

  • No pages visited yet.

Most visited

  • No pages visited yet.
// gaming

Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware

Cybercriminals are exploiting intense curiosity in Grand Theft Auto VI by pushing faux sport downloads that set up a number of sorts of malware as an alternative of a playable sport. The marketing campaign targets folks searching for an early construct, leaked copy, or unofficial demo earlier than the title’s launch.

The malicious downloads are distributed by poisoned search outcomes, gaming boards, torrent websites, and social-media posts. A number of the faux ISO information exceed 100GB, however the massive dimension is principally junk knowledge supposed to make the obtain seem plausible.

Analysts at Huntress recognized a pattern that mixed remote-access malware, an info stealer, file-destroying ransomware, and an additional net browser in a single package deal.

Using Russian-language prompts and a Russian ransom word suggests the operation could also be aimed primarily at Russian-speaking avid gamers.

Huntress said in a report shared with Cyber Safety Information (CSN) that the marketing campaign abuses the absence of any reputable GTA 6 demo or leaked playable construct.

Icon for the main installer file (Source - Huntress)
Icon for the principle installer file (Supply – Huntress)

The case exhibits how a high-profile sport launch can flip unusual searches right into a route for system compromise, just like earlier fake GTA 6 demo malware exercise focusing on keen gamers.

Fake GTA 6 Downloads Deliver Multiple Threats

The infection begins when a victim mounts the fake game image and launches what appears to be an installer. The main program uses an older GTA 5-style icon, then displays a Russian message warning that the supposed leaked game may fail because its crack is no longer valid.

That warning is part of the deception. Once the installation finishes, victims see a “license not found” error, giving them a believable reason why the game did not open while malware runs quietly in the background.

This approach helps attackers delay suspicion and gives their payloads more time to operate. The package drops several files into the Windows temporary folder and checks whether the device can reach the internet before continuing.

It then installs multiple copies of NJRAT, a remote-access tool that can let an attacker record keystrokes, capture screenshots, access webcams, browse files, steal browser data, and remotely control the system.

Message contained within the fake GTA6 installer (Source - Huntress)
Message contained within the fake GTA6 installer (Source – Huntress)

The attackers also deploy DCRAT, another remote-access tool that can monitor windows, capture the clipboard, discover audio devices, and change registry settings.

It changes the Windows hosts file to block selected telemetry and security-reporting services, a tactic that may reduce the chance of the infection being noticed or reported.

A separate component, Mercurial Grabber, collects browser passwords and cookies, chat-platform tokens, game-related session data, screenshots, system details, location information, and Windows product keys.

The campaign reflects the same broad risk seen in SEO poisoned download campaigns, the place trusted-looking search outcomes lead customers to weaponized installers.

Ransomware Used as a Wiper

The most damaging part of the package is Chaos ransomware, although the operators do not appear interested in collecting payment.

Instead, the malware acts like a wiper by encrypting smaller files and overwriting files larger than 200MB with random data, making them effectively unrecoverable.

If the infected user has administrator rights, the malware deletes shadow copies and disables recovery options before starting file destruction.

It targets common personal folders, shared data locations, saved games, and cloud-synchronised storage, creating a damaging outcome that can extend beyond the device itself.

Error message (Source - Huntress)
Error message (Source – Huntress)

The ransomware leaves a note claiming files have been encrypted forever, rather than giving victims a genuine recovery path.

That behavior makes the campaign especially dangerous for gamers who may expect only password theft but instead lose documents, photos, game saves, and locally stored work files.

Users should avoid alleged unreleased games, pirated installers, and download pages promoted through unfamiliar search results.

Search-result manipulation remains a recurring delivery method, as shown by malicious software search results that imitate reputable obtain sources to lure Home windows customers.

Anyone who ran a suspected GTA 6 installer should immediately disconnect the device from the network, reset passwords from a clean device, enable two-factor authentication, and perform a full system reinstallation.

Keeping security protections updated can also help detect the older malware families used in this operation. The campaign is a reminder that popular games create a ready-made social-engineering opportunity.

Players should wait for announcements and downloads from official publisher channels, rather than trusting leaked-build claims, torrent listings, or posts promising early access.

Indicators of Compromise (IoCs):-

Type Indicator Description
File name / MD5 Gta6installer.exe
a15e280a3fd65dfaa243bbe2dbf45e97
Initial fake installation executable
File name / MD5 %TEMP%checkinternetconnection.bat
6b49f24d5d5b49127476bc385565f8b0
Batch file used to confirm internet connectivity
File names / MD5s %TEMP%licensechecker.exe%TEMP%rockstar.exe%TEMP%steam.exe%TEMP%any.ran.exe%TEMP%svchost.exe%TEMP%abc.exe%TEMP%license.exe%TEMP%rockstargamescrashfixer.exe%TEMP%rockstarservices.exe
2a0834560ed3770fc33d7a42f8229722
57b9c56ef97a7ada98257b23577bf5e3
60a0f58001ea7be538cd42b651924cc7
15eca4a3f7350423cf4db0b4c30d1968
ea991bc9334b36a6b958f564ee716776
2a385fe7bed9899d77d05cb8e302d557
NJRAT copies and associated launchers
IP addresses 35.157.111[.]131
3.68.56[.]232
3.67.15[.]169
Infrastructure contacted by NJRAT
Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT
File names / MD5 %TEMP%rockstargames.exe%TEMP%P3usMXh1h4.batC:UsersDefaultLocal Settings[RANDOM FILE NAME].exe
8da3fe3664d81226b0fb2a50a0537d4f
DCRAT installer components and binary
Hosts-file entries 0.0.0.0 app.adjust.com
0.0.0.0 app.adjust.io
0.0.0.0 app-sj01.marketo.com
0.0.0.0 t.appsflyer.com
0.0.0.0 analytics.ff.avast.com
0.0.0.0 analytics.ns1.ff.avast.com
0.0.0.0 v7event.stats.avcdn.net
0.0.0.0 v7.stats.avcdn.net
0.0.0.0 ads.avocet.io
0.0.0.0 telemetry.battle.net
0.0.0.0 analytics.rollout.io
0.0.0.0 metrics.ol.epicgames.com
0.0.0.0 a.fiksu.com
0.0.0.0 sdk.fiksu.com
0.0.0.0 settings.crashlytics.com
0.0.0.0 e.crashlytics.com
0.0.0.0 insights-collector.gog.com
0.0.0.0 ssl.google-analytics.com
0.0.0.0 ssl-google-analytics.l.google.com
0.0.0.0 static.hotjar.com
0.0.0.0 flow.lavasoft.com
0.0.0.0 telemetry.servers.getgo.com
0.0.0.0 telemetry.malwarebytes.com
0.0.0.0 ws.mcafee.com
0.0.0.0 analytics.ccs.mcafee.com
0.0.0.0 analyticsdcs.ccs.mcafee.com
0.0.0.0 gate.hockeyapp.net
0.0.0.0 api.mixpanel.com
0.0.0.0 decide.mixpanel.com
0.0.0.0 ads.mopub.com
0.0.0.0 incoming.telemetry.mozilla.org
0.0.0.0 h.online-metrix.net
0.0.0.0 analytics.paddle.com
0.0.0.0 treasuredata.com
0.0.0.0 in.treasuredata.com
0.0.0.0 redshell.io
0.0.0.0 api.redshell.io
0.0.0.0 carcharodon.trendmicro.com
0.0.0.0 cdn.segment.com
0.0.0.0 api.segment.io
0.0.0.0 mobile-service.segment.com
Entries added to the Windows hosts file by DCRAT
Domain / IP address a0700877.xsph[.]ru
141.8.197[.]42
DCRAT command-and-control infrastructure
File name / MD5 %TEMP%adminapp.exe
dfdf5e5b78d2ec764c0e5641cf9a0d26
Mercurial Grabber infostealer binary
URL https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y0M_A86oJHp00O-l8F4jakfVhqFXzMBoy1uBDdj2rBLc Discord webhook used for stolen-data exfiltration
File names / MD5 %TEMP%gta6.exe%USERPROFILE%AppDataRoamingsvchost.exe
b9648ec8cc806e7661aabcfc91dc836c
Chaos ransomware binaries
File name read_it.txt Note dropped in folders affected by Chaos ransomware
File name / MD5 %TEMP%YandexPackLoader.exe
1ec9eff863dc4418d1498bc3d904899d
Browser installer included in the malicious ISO
File name / MD5 %TEMP%find.vbs
0e39e8d7b641bcda4376ebbfeff7b12e
Script that displays the fake “license not found” message
Email address kanalwsegokrytowo555@gmail.com Address displayed by the fake installer for alleged crack updates

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Source link