Cybercriminals are exploiting intense curiosity in Grand Theft Auto VI by pushing faux sport downloads that set up a number of sorts of malware as an alternative of a playable sport. The marketing campaign targets folks searching for an early construct, leaked copy, or unofficial demo earlier than the title’s launch.
The malicious downloads are distributed by poisoned search outcomes, gaming boards, torrent websites, and social-media posts. A number of the faux ISO information exceed 100GB, however the massive dimension is principally junk knowledge supposed to make the obtain seem plausible.
Analysts at Huntress recognized a pattern that mixed remote-access malware, an info stealer, file-destroying ransomware, and an additional net browser in a single package deal.
Using Russian-language prompts and a Russian ransom word suggests the operation could also be aimed primarily at Russian-speaking avid gamers.
Huntress said in a report shared with Cyber Safety Information (CSN) that the marketing campaign abuses the absence of any reputable GTA 6 demo or leaked playable construct.
The case exhibits how a high-profile sport launch can flip unusual searches right into a route for system compromise, just like earlier fake GTA 6 demo malware exercise focusing on keen gamers.
Fake GTA 6 Downloads Deliver Multiple Threats
The infection begins when a victim mounts the fake game image and launches what appears to be an installer. The main program uses an older GTA 5-style icon, then displays a Russian message warning that the supposed leaked game may fail because its crack is no longer valid.
That warning is part of the deception. Once the installation finishes, victims see a “license not found” error, giving them a believable reason why the game did not open while malware runs quietly in the background.
This approach helps attackers delay suspicion and gives their payloads more time to operate. The package drops several files into the Windows temporary folder and checks whether the device can reach the internet before continuing.
It then installs multiple copies of NJRAT, a remote-access tool that can let an attacker record keystrokes, capture screenshots, access webcams, browse files, steal browser data, and remotely control the system.
The attackers also deploy DCRAT, another remote-access tool that can monitor windows, capture the clipboard, discover audio devices, and change registry settings.
It changes the Windows hosts file to block selected telemetry and security-reporting services, a tactic that may reduce the chance of the infection being noticed or reported.
A separate component, Mercurial Grabber, collects browser passwords and cookies, chat-platform tokens, game-related session data, screenshots, system details, location information, and Windows product keys.
The campaign reflects the same broad risk seen in SEO poisoned download campaigns, the place trusted-looking search outcomes lead customers to weaponized installers.
Ransomware Used as a Wiper
The most damaging part of the package is Chaos ransomware, although the operators do not appear interested in collecting payment.
Instead, the malware acts like a wiper by encrypting smaller files and overwriting files larger than 200MB with random data, making them effectively unrecoverable.
If the infected user has administrator rights, the malware deletes shadow copies and disables recovery options before starting file destruction.
It targets common personal folders, shared data locations, saved games, and cloud-synchronised storage, creating a damaging outcome that can extend beyond the device itself.
The ransomware leaves a note claiming files have been encrypted forever, rather than giving victims a genuine recovery path.
That behavior makes the campaign especially dangerous for gamers who may expect only password theft but instead lose documents, photos, game saves, and locally stored work files.
Users should avoid alleged unreleased games, pirated installers, and download pages promoted through unfamiliar search results.
Search-result manipulation remains a recurring delivery method, as shown by malicious software search results that imitate reputable obtain sources to lure Home windows customers.
Anyone who ran a suspected GTA 6 installer should immediately disconnect the device from the network, reset passwords from a clean device, enable two-factor authentication, and perform a full system reinstallation.
Keeping security protections updated can also help detect the older malware families used in this operation. The campaign is a reminder that popular games create a ready-made social-engineering opportunity.
Players should wait for announcements and downloads from official publisher channels, rather than trusting leaked-build claims, torrent listings, or posts promising early access.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| File name / MD5 | Gta6installer.exea15e280a3fd65dfaa243bbe2dbf45e97 |
Initial fake installation executable |
| File name / MD5 | %TEMP%checkinternetconnection.bat6b49f24d5d5b49127476bc385565f8b0 |
Batch file used to confirm internet connectivity |
| File names / MD5s | %TEMP%licensechecker.exe, %TEMP%rockstar.exe, %TEMP%steam.exe, %TEMP%any.ran.exe, %TEMP%svchost.exe, %TEMP%abc.exe, %TEMP%license.exe, %TEMP%rockstargamescrashfixer.exe, %TEMP%rockstarservices.exe2a0834560ed3770fc33d7a42f822972257b9c56ef97a7ada98257b23577bf5e360a0f58001ea7be538cd42b651924cc715eca4a3f7350423cf4db0b4c30d1968ea991bc9334b36a6b958f564ee7167762a385fe7bed9899d77d05cb8e302d557 |
NJRAT copies and associated launchers |
| IP addresses | 35.157.111[.]1313.68.56[.]2323.67.15[.]169 |
Infrastructure contacted by NJRAT |
| Domain / Port | 7.tcp.eu.ngrok[.]io:12684 |
ngrok endpoint contacted by NJRAT |
| File names / MD5 | %TEMP%rockstargames.exe, %TEMP%P3usMXh1h4.bat, C:UsersDefaultLocal Settings[RANDOM FILE NAME].exe8da3fe3664d81226b0fb2a50a0537d4f |
DCRAT installer components and binary |
| Hosts-file entries | 0.0.0.0 app.adjust.com0.0.0.0 app.adjust.io0.0.0.0 app-sj01.marketo.com0.0.0.0 t.appsflyer.com0.0.0.0 analytics.ff.avast.com0.0.0.0 analytics.ns1.ff.avast.com0.0.0.0 v7event.stats.avcdn.net0.0.0.0 v7.stats.avcdn.net0.0.0.0 ads.avocet.io0.0.0.0 telemetry.battle.net0.0.0.0 analytics.rollout.io0.0.0.0 metrics.ol.epicgames.com0.0.0.0 a.fiksu.com0.0.0.0 sdk.fiksu.com0.0.0.0 settings.crashlytics.com0.0.0.0 e.crashlytics.com0.0.0.0 insights-collector.gog.com0.0.0.0 ssl.google-analytics.com0.0.0.0 ssl-google-analytics.l.google.com0.0.0.0 static.hotjar.com0.0.0.0 flow.lavasoft.com0.0.0.0 telemetry.servers.getgo.com0.0.0.0 telemetry.malwarebytes.com0.0.0.0 ws.mcafee.com0.0.0.0 analytics.ccs.mcafee.com0.0.0.0 analyticsdcs.ccs.mcafee.com0.0.0.0 gate.hockeyapp.net0.0.0.0 api.mixpanel.com0.0.0.0 decide.mixpanel.com0.0.0.0 ads.mopub.com0.0.0.0 incoming.telemetry.mozilla.org0.0.0.0 h.online-metrix.net0.0.0.0 analytics.paddle.com0.0.0.0 treasuredata.com0.0.0.0 in.treasuredata.com0.0.0.0 redshell.io0.0.0.0 api.redshell.io0.0.0.0 carcharodon.trendmicro.com0.0.0.0 cdn.segment.com0.0.0.0 api.segment.io0.0.0.0 mobile-service.segment.com |
Entries added to the Windows hosts file by DCRAT |
| Domain / IP address | a0700877.xsph[.]ru141.8.197[.]42 |
DCRAT command-and-control infrastructure |
| File name / MD5 | %TEMP%adminapp.exedfdf5e5b78d2ec764c0e5641cf9a0d26 |
Mercurial Grabber infostealer binary |
| URL | https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y0M_A86oJHp00O-l8F4jakfVhqFXzMBoy1uBDdj2rBLc |
Discord webhook used for stolen-data exfiltration |
| File names / MD5 | %TEMP%gta6.exe, %USERPROFILE%AppDataRoamingsvchost.exeb9648ec8cc806e7661aabcfc91dc836c |
Chaos ransomware binaries |
| File name | read_it.txt |
Note dropped in folders affected by Chaos ransomware |
| File name / MD5 | %TEMP%YandexPackLoader.exe1ec9eff863dc4418d1498bc3d904899d |
Browser installer included in the malicious ISO |
| File name / MD5 | %TEMP%find.vbs0e39e8d7b641bcda4376ebbfeff7b12e |
Script that displays the fake “license not found” message |
| Email address | kanalwsegokrytowo555@gmail.com |
Address displayed by the fake installer for alleged crack updates |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.
