GBHackers

Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers


Threat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information.

A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer.

The campaign demonstrates how cybercriminals are turning one of gaming’s most anticipated releases into a high-volume initial-access lure.

GTA 6 is scheduled to launch on November 19, 2026, for PlayStation 5 and Xbox Series X|S, meaning any supposed early playable build circulating through torrents, gaming forums, social media, or search results should be treated as malicious.

Rockstar has not announced a PC release date, making “GTA 6 PC crack” and “leaked GTA 6 ISO” searches particularly attractive targets for SEO-poisoning operators.

Huntress observed attackers promoting fake GTA 6 ISO files through search-engine manipulation, torrent sites, gaming communities, and social-media posts.

Some downloads exceed 100 GB, apparently to mimic the size expected from a modern AAA title.

However, researchers said the oversized images are largely padded with junk data, while the malicious executable payloads are comparatively small.

The analyzed ISO presents users with gta6installer.exe, which oddly uses a GTA 5-style icon.

When launched, the installer displays a Russian-language prompt claiming the software is an unlicensed, leaked build and warning that it may generate a “License not found” error.

It also provides an email address for users to request an updated crack.

That message is central to the social-engineering chain. Once background malware deployment is complete, a Visual Basic script intentionally displays the promised “license not found” error.

The victim is left believing the pirated game simply failed to run, rather than recognizing that multiple payloads have already been installed.

The installer stages files in the Windows %TEMP% directory using names designed to appear game-related, including rockstar.exe, steam.exe, licensechecker.exe, gta6.exe, and adminapp.exe.

A batch file first opens Microsoft Edge to verify internet access through a shortened URL, then proceeds to unpack the malware components.

Several of those files deploy NJRAT, a remote-access trojan with extensive surveillance and theft capabilities.

The malware can open a remote shell, log keystrokes, capture screenshots, access connected cameras, steal browser passwords, manipulate files and Registry entries, and collect cryptocurrency details.

Huntress said in a report shared with GBhackers, a malicious ISO image disguised as a playable GTA 6 leak and found that it combined multiple remote-access trojans, an open-source infostealer.

The samples add Windows Firewall rules and communicate with AWS-hosted infrastructure as well as an ngrok tunneling endpoint, potentially allowing operators to maintain remote control over infected systems.

Message contained within the fake GTA6 installer (Source : Huntress).

Another component installs DCRAT under a randomized filename in C:UsersDefaultLocal Settings. DCRAT provides mouse control, clipboard access, screenshot capture, window tracking, audio-device discovery, and Registry read/write access.

Fake GTA 6 Installer

Huntress also found that the associated loader modified the Windows hosts file to interfere with telemetry and residential antivirus reporting services.

The ISO additionally drops adminapp.exe, identified as the Mercurial Grabber infostealer.

The tool harvests Google Chrome passwords and cookies, Discord tokens, Roblox Studio cookies, Minecraft session data, Windows product keys, screenshots, system metadata, IP addresses, and geolocation information.

The ransomware encrypts files 200MB and smaller, by first creating a random password of 20 characters, then using it to run AES encryption, and finally adding a random four-character extension to the files.

The stolen data is then exfiltrated through an attacker-controlled Discord webhook.

 Ransomware note (Source : Huntress).
 Ransomware note (Source : Huntress).

The targeting of Discord and game-session artifacts makes the campaign particularly risky for gamers, who may use browser-saved credentials, maintain valuable in-game accounts, store cryptocurrency-wallet extensions, or hold privileged Discord community roles.

The most destructive payload is a Chaos ransomware variant launched through gta6.exe. Rather than pursuing payment, the malware appears designed to disrupt victims permanently.

It deletes shadow-copy backups, disables Windows recovery options, encrypts files 200 MB or smaller with AES, and overwrites larger files with random data.

This turns the ransomware into an effective wiper, especially for users without offline backups.

The malware prioritizes non-system drives and then targets common user folders, including Desktop, Documents, Downloads, Pictures, Saved Games, AppData, and OneDrive locations.

It leaves behind a read_it.txt note claiming the files are encrypted forever and changes the wallpaper to a Russian-language message attributed to the “ASHA Hacker Team.”

The campaign reinforces a straightforward security rule: no legitimate GTA 6 leak, demo, or crack should be trusted before the official release.

Gamers should avoid torrent-hosted ISOs, pirated installers, and search-result advertisements claiming early access; keep Microsoft Defender or another endpoint product updated.

Use unique passwords and MFA; revoke Discord sessions if compromise is suspected; and restore affected systems only after a full rebuild from known-clean media.

IOCs

ItemDescription
Gta6installer.exeMD5a15e280a3fd65dfaa243bbe2dbf45e97Initial installation executable
%TEMP%checkinternetconnection.batMD5:6b49f24d5d5b49127476bc385565f8b0BAT file used to confirm a working internet connection
%TEMP%licensechecker.exe%TEMP%rockstar.exe%TEMP%steam.exe%TEMP%any.ran.exe%TEMP%svchost.exe%TEMP%abc.exe%TEMP%license.exe%TEMP%rockstargamescrashfixer.exe %TEMP%rockstarservices.exe MD5s:2a0834560ed3770fc33d7a42f822972257b9c56ef97a7ada98257b23577bf5e360a0f58001ea7be538cd42b651924cc715eca4a3f7350423cf4db0b4c30d1968Ea991bc9334b36a6b958f564ee7167762a385fe7bed9899d77d05cb8e302d557Copies of NJRAT and associated launchers

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.



Source link