CyberSecurityNews

Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware


Cybercriminals are exploiting intense interest in Grand Theft Auto VI by pushing fake game downloads that install several types of malware instead of a playable game. The campaign targets people looking for an early build, leaked copy, or unofficial demo before the title’s release.

The malicious downloads are distributed through poisoned search results, gaming forums, torrent sites, and social-media posts. Some of the fake ISO files exceed 100GB, but the large size is mainly junk data intended to make the download appear believable.

Analysts at Huntress identified a sample that combined remote-access malware, an information stealer, file-destroying ransomware, and an extra web browser in one package.

The use of Russian-language prompts and a Russian ransom note suggests the operation may be aimed primarily at Russian-speaking gamers.

Huntress said in a report shared with Cyber Security News (CSN) that the campaign abuses the absence of any legitimate GTA 6 demo or leaked playable build.

Icon for the main installer file (Source – Huntress)

The case shows how a high-profile game release can turn ordinary searches into a route for device compromise, similar to earlier fake GTA 6 demo malware activity targeting eager players.

Fake GTA 6 Downloads Deliver Multiple Threats

The infection begins when a victim mounts the fake game image and launches what appears to be an installer. The main program uses an older GTA 5-style icon, then displays a Russian message warning that the supposed leaked game may fail because its crack is no longer valid.

That warning is part of the deception. Once the installation finishes, victims see a “license not found” error, giving them a believable reason why the game did not open while malware runs quietly in the background.

This approach helps attackers delay suspicion and gives their payloads more time to operate. The package drops several files into the Windows temporary folder and checks whether the device can reach the internet before continuing.

It then installs multiple copies of NJRAT, a remote-access tool that can let an attacker record keystrokes, capture screenshots, access webcams, browse files, steal browser data, and remotely control the system.

Message contained within the fake GTA6 installer (Source - Huntress)
Message contained within the fake GTA6 installer (Source – Huntress)

The attackers also deploy DCRAT, another remote-access tool that can monitor windows, capture the clipboard, discover audio devices, and change registry settings.

It changes the Windows hosts file to block selected telemetry and security-reporting services, a tactic that may reduce the chance of the infection being noticed or reported.

A separate component, Mercurial Grabber, collects browser passwords and cookies, chat-platform tokens, game-related session data, screenshots, system details, location information, and Windows product keys.

The campaign reflects the same broad risk seen in SEO poisoned download campaigns, where trusted-looking search results lead users to weaponized installers.

Ransomware Used as a Wiper

The most damaging part of the package is Chaos ransomware, although the operators do not appear interested in collecting payment.

Instead, the malware acts like a wiper by encrypting smaller files and overwriting files larger than 200MB with random data, making them effectively unrecoverable.

If the infected user has administrator rights, the malware deletes shadow copies and disables recovery options before starting file destruction.

It targets common personal folders, shared data locations, saved games, and cloud-synchronised storage, creating a damaging outcome that can extend beyond the device itself.

Error message (Source - Huntress)
Error message (Source – Huntress)

The ransomware leaves a note claiming files have been encrypted forever, rather than giving victims a genuine recovery path.

That behavior makes the campaign especially dangerous for gamers who may expect only password theft but instead lose documents, photos, game saves, and locally stored work files.

Users should avoid alleged unreleased games, pirated installers, and download pages promoted through unfamiliar search results.

Search-result manipulation remains a recurring delivery method, as shown by malicious software search results that imitate legitimate download sources to lure Windows users.

Anyone who ran a suspected GTA 6 installer should immediately disconnect the device from the network, reset passwords from a clean device, enable two-factor authentication, and perform a full system reinstallation.

Keeping security protections updated can also help detect the older malware families used in this operation. The campaign is a reminder that popular games create a ready-made social-engineering opportunity.

Players should wait for announcements and downloads from official publisher channels, rather than trusting leaked-build claims, torrent listings, or posts promising early access.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
File name / MD5Gta6installer.exe
a15e280a3fd65dfaa243bbe2dbf45e97
Initial fake installation executable
File name / MD5%TEMP%checkinternetconnection.bat
6b49f24d5d5b49127476bc385565f8b0
Batch file used to confirm internet connectivity
File names / MD5s%TEMP%licensechecker.exe%TEMP%rockstar.exe%TEMP%steam.exe%TEMP%any.ran.exe%TEMP%svchost.exe%TEMP%abc.exe%TEMP%license.exe%TEMP%rockstargamescrashfixer.exe%TEMP%rockstarservices.exe
2a0834560ed3770fc33d7a42f8229722
57b9c56ef97a7ada98257b23577bf5e3
60a0f58001ea7be538cd42b651924cc7
15eca4a3f7350423cf4db0b4c30d1968
ea991bc9334b36a6b958f564ee716776
2a385fe7bed9899d77d05cb8e302d557
NJRAT copies and associated launchers
IP addresses35.157.111[.]131
3.68.56[.]232
3.67.15[.]169
Infrastructure contacted by NJRAT
Domain / Port7.tcp.eu.ngrok[.]io:12684ngrok endpoint contacted by NJRAT
File names / MD5%TEMP%rockstargames.exe%TEMP%P3usMXh1h4.batC:UsersDefaultLocal Settings[RANDOM FILE NAME].exe
8da3fe3664d81226b0fb2a50a0537d4f
DCRAT installer components and binary
Hosts-file entries0.0.0.0 app.adjust.com
0.0.0.0 app.adjust.io
0.0.0.0 app-sj01.marketo.com
0.0.0.0 t.appsflyer.com
0.0.0.0 analytics.ff.avast.com
0.0.0.0 analytics.ns1.ff.avast.com
0.0.0.0 v7event.stats.avcdn.net
0.0.0.0 v7.stats.avcdn.net
0.0.0.0 ads.avocet.io
0.0.0.0 telemetry.battle.net
0.0.0.0 analytics.rollout.io
0.0.0.0 metrics.ol.epicgames.com
0.0.0.0 a.fiksu.com
0.0.0.0 sdk.fiksu.com
0.0.0.0 settings.crashlytics.com
0.0.0.0 e.crashlytics.com
0.0.0.0 insights-collector.gog.com
0.0.0.0 ssl.google-analytics.com
0.0.0.0 ssl-google-analytics.l.google.com
0.0.0.0 static.hotjar.com
0.0.0.0 flow.lavasoft.com
0.0.0.0 telemetry.servers.getgo.com
0.0.0.0 telemetry.malwarebytes.com
0.0.0.0 ws.mcafee.com
0.0.0.0 analytics.ccs.mcafee.com
0.0.0.0 analyticsdcs.ccs.mcafee.com
0.0.0.0 gate.hockeyapp.net
0.0.0.0 api.mixpanel.com
0.0.0.0 decide.mixpanel.com
0.0.0.0 ads.mopub.com
0.0.0.0 incoming.telemetry.mozilla.org
0.0.0.0 h.online-metrix.net
0.0.0.0 analytics.paddle.com
0.0.0.0 treasuredata.com
0.0.0.0 in.treasuredata.com
0.0.0.0 redshell.io
0.0.0.0 api.redshell.io
0.0.0.0 carcharodon.trendmicro.com
0.0.0.0 cdn.segment.com
0.0.0.0 api.segment.io
0.0.0.0 mobile-service.segment.com
Entries added to the Windows hosts file by DCRAT
Domain / IP addressa0700877.xsph[.]ru
141.8.197[.]42
DCRAT command-and-control infrastructure
File name / MD5%TEMP%adminapp.exe
dfdf5e5b78d2ec764c0e5641cf9a0d26
Mercurial Grabber infostealer binary
URLhttps://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y0M_A86oJHp00O-l8F4jakfVhqFXzMBoy1uBDdj2rBLcDiscord webhook used for stolen-data exfiltration
File names / MD5%TEMP%gta6.exe%USERPROFILE%AppDataRoamingsvchost.exe
b9648ec8cc806e7661aabcfc91dc836c
Chaos ransomware binaries
File nameread_it.txtNote dropped in folders affected by Chaos ransomware
File name / MD5%TEMP%YandexPackLoader.exe
1ec9eff863dc4418d1498bc3d904899d
Browser installer included in the malicious ISO
File name / MD5%TEMP%find.vbs
0e39e8d7b641bcda4376ebbfeff7b12e
Script that displays the fake “license not found” message
Email addresskanalwsegokrytowo555@gmail.comAddress displayed by the fake installer for alleged crack updates

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.



Source link