Cybersecurity firm Huntress has uncovered a malware campaign that preys on excitement for Grand Theft Auto VI (GTA6), packaging remote access trojans, an infostealer, and destructive ransomware inside fake “leaked” copies of the hotly anticipated game.
GTA6 is not due for release for another three months, but a wave of gameplay footage leaks and an official extended look from publisher Rockstar Games have pushed fan anticipation to a fever pitch. Threat actors have moved quickly to capitalise, seeding search results, gaming forums, social media and torrent sites with bogus disc image (ISO) files claiming to offer early access to the game. According to Huntress, no genuine leaked or playable version of GTA6 currently exists.
A booby-trapped installer
Some of the fake ISOs circulating exceed 100GB, padded with junk data to mimic the footprint of a legitimate AAA release, Huntress found. The actual malicious payload is far smaller, hidden inside a bundle that the researchers describe as an opportunistic attempt to throw “everything” at anyone who runs the installer.
Opening the ISO presents victims with a file named gta6installer.exe, oddly bearing the GTA5 icon rather than GTA6. Running it displays a Russian-language message warning that the game is unlicensed and may not launch, instructing users to email the attackers if they hit a “License not found” error so the “crack” can be fixed. That error message duly appears once installation finishes, a scripted piece of misdirection designed to explain away the fact that no game ever appears, while malware installs quietly in the background.
Three RATs, an infostealer, and a wiper
Beneath the fake installer, Huntress catalogued a small arsenal of malware, much of it several years old and simply repurposed for this campaign. Multiple copies of the remote access trojan NJRAT are dropped onto the system, along with a separate instance of DCRAT, giving attackers the ability to log keystrokes, access webcams, browse the desktop, steal browser credentials and cryptocurrency wallet details, and take full remote control of infected machines.
An open-source infostealer called Mercurial Grabber, nominally billed as an educational tool, is also installed, harvesting Discord tokens, Chrome-saved passwords and cookies, Roblox and Minecraft session data, Windows product keys and system information, and exfiltrating it all via a Discord webhook.
Most damaging is a variant of the well-known Chaos ransomware family, which Huntress says is being used purely as a wiper rather than for financial extortion. Once triggered on a machine with administrator rights, it deletes shadow copy backups, disables Windows recovery options, then either encrypts files under 200MB or overwrites larger files with random data, destroying them outright. It targets desktop, document, picture, and OneDrive folders, before changing the desktop wallpaper to an image of SpongeBob SquarePants declaring the machine hacked by the “Asha Hacker Team” and leaving a ransom note that provides no actual payment method.
The installer additionally drops a copy of Yandex Browser, a service popular in Russia and Eastern Europe. Combined with the Russian-language prompts and ransom messaging, Huntress believes the campaign is primarily targeting Russian-speaking gamers, although the tactics could easily be redeployed against fans elsewhere.
Old malware, same old lure
Huntress notes that none of the individual malware components are new or particularly sophisticated, and that an up-to-date version of Windows Defender should detect and block each one. The bigger risk, researchers say, lies in the social engineering: impatient fans searching for an early copy of a major game release are unusually willing to override security warnings and run unverified executables.
The firm’s advice is straightforward. Avoid downloading cracked or pirated software, especially for games not yet officially released. Anyone who believes they have already run the installer should disconnect the affected machine from the network immediately, reset passwords, enable two-factor authentication wherever possible, and fully reimage the system rather than attempt to clean it.
Huntress has published full technical indicators of compromise, including file hashes, dropped file paths, and command-and-control infrastructure, alongside its analysis. It can be found here: https://www.huntress.com/blog/fake-gta6-download-malware-analysis

