Cybercriminals are exploiting intense interest in Grand Theft Auto VI by pushing fake game downloads that install several types of malware instead of a playable game. The campaign targets people looking for an early build, leaked copy, or unofficial demo before the title’s release.
The malicious downloads are distributed through poisoned search results, gaming forums, torrent sites, and social-media posts. Some of the fake ISO files exceed 100GB, but the large size is mainly junk data intended to make the download appear believable.
Analysts at Huntress identified a sample that combined remote-access malware, an information stealer, file-destroying ransomware, and an extra web browser in one package.
The use of Russian-language prompts and a Russian ransom note suggests the operation may be aimed primarily at Russian-speaking gamers.
Huntress said in a report shared with Cyber Security News (CSN) that the campaign abuses the absence of any legitimate GTA 6 demo or leaked playable build.
The case shows how a high-profile game release can turn ordinary searches into a route for device compromise, similar to earlier fake GTA 6 demo malware activity targeting eager players.
Fake GTA 6 Downloads Deliver Multiple Threats
The infection begins when a victim mounts the fake game image and launches what appears to be an installer. The main program uses an older GTA 5-style icon, then displays a Russian message warning that the supposed leaked game may fail because its crack is no longer valid.
That warning is part of the deception. Once the installation finishes, victims see a “license not found” error, giving them a believable reason why the game did not open while malware runs quietly in the background.
This approach helps attackers delay suspicion and gives their payloads more time to operate. The package drops several files into the Windows temporary folder and checks whether the device can reach the internet before continuing.
It then installs multiple copies of NJRAT, a remote-access tool that can let an attacker record keystrokes, capture screenshots, access webcams, browse files, steal browser data, and remotely control the system.
The attackers also deploy DCRAT, another remote-access tool that can monitor windows, capture the clipboard, discover audio devices, and change registry settings.
It changes the Windows hosts file to block selected telemetry and security-reporting services, a tactic that may reduce the chance of the infection being noticed or reported.
A separate component, Mercurial Grabber, collects browser passwords and cookies, chat-platform tokens, game-related session data, screenshots, system details, location information, and Windows product keys.
The campaign reflects the same broad risk seen in SEO poisoned download campaigns, where trusted-looking search results lead users to weaponized installers.
Ransomware Used as a Wiper
The most damaging part of the package is Chaos ransomware, although the operators do not appear interested in collecting payment.
Instead, the malware acts like a wiper by encrypting smaller files and overwriting files larger than 200MB with random data, making them effectively unrecoverable.
If the infected user has administrator rights, the malware deletes shadow copies and disables recovery options before starting file destruction.
It targets common personal folders, shared data locations, saved games, and cloud-synchronised storage, creating a damaging outcome that can extend beyond the device itself.
The ransomware leaves a note claiming files have been encrypted forever, rather than giving victims a genuine recovery path.
That behavior makes the campaign especially dangerous for gamers who may expect only password theft but instead lose documents, photos, game saves, and locally stored work files.
Users should avoid alleged unreleased games, pirated installers, and download pages promoted through unfamiliar search results.
Search-result manipulation remains a recurring delivery method, as shown by malicious software search results that imitate legitimate download sources to lure Windows users.
Anyone who ran a suspected GTA 6 installer should immediately disconnect the device from the network, reset passwords from a clean device, enable two-factor authentication, and perform a full system reinstallation.
Keeping security protections updated can also help detect the older malware families used in this operation. The campaign is a reminder that popular games create a ready-made social-engineering opportunity.
Players should wait for announcements and downloads from official publisher channels, rather than trusting leaked-build claims, torrent listings, or posts promising early access.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| File name / MD5 | Gta6installer.exea15e280a3fd65dfaa243bbe2dbf45e97 | Initial fake installation executable |
| File name / MD5 | %TEMP%checkinternetconnection.bat6b49f24d5d5b49127476bc385565f8b0 | Batch file used to confirm internet connectivity |
| File names / MD5s | %TEMP%licensechecker.exe, %TEMP%rockstar.exe, %TEMP%steam.exe, %TEMP%any.ran.exe, %TEMP%svchost.exe, %TEMP%abc.exe, %TEMP%license.exe, %TEMP%rockstargamescrashfixer.exe, %TEMP%rockstarservices.exe2a0834560ed3770fc33d7a42f822972257b9c56ef97a7ada98257b23577bf5e360a0f58001ea7be538cd42b651924cc715eca4a3f7350423cf4db0b4c30d1968ea991bc9334b36a6b958f564ee7167762a385fe7bed9899d77d05cb8e302d557 | NJRAT copies and associated launchers |
| IP addresses | 35.157.111[.]1313.68.56[.]2323.67.15[.]169 | Infrastructure contacted by NJRAT |
| Domain / Port | 7.tcp.eu.ngrok[.]io:12684 | ngrok endpoint contacted by NJRAT |
| File names / MD5 | %TEMP%rockstargames.exe, %TEMP%P3usMXh1h4.bat, C:UsersDefaultLocal Settings[RANDOM FILE NAME].exe8da3fe3664d81226b0fb2a50a0537d4f | DCRAT installer components and binary |
| Hosts-file entries | 0.0.0.0 app.adjust.com0.0.0.0 app.adjust.io0.0.0.0 app-sj01.marketo.com0.0.0.0 t.appsflyer.com0.0.0.0 analytics.ff.avast.com0.0.0.0 analytics.ns1.ff.avast.com0.0.0.0 v7event.stats.avcdn.net0.0.0.0 v7.stats.avcdn.net0.0.0.0 ads.avocet.io0.0.0.0 telemetry.battle.net0.0.0.0 analytics.rollout.io0.0.0.0 metrics.ol.epicgames.com0.0.0.0 a.fiksu.com0.0.0.0 sdk.fiksu.com0.0.0.0 settings.crashlytics.com0.0.0.0 e.crashlytics.com0.0.0.0 insights-collector.gog.com0.0.0.0 ssl.google-analytics.com0.0.0.0 ssl-google-analytics.l.google.com0.0.0.0 static.hotjar.com0.0.0.0 flow.lavasoft.com0.0.0.0 telemetry.servers.getgo.com0.0.0.0 telemetry.malwarebytes.com0.0.0.0 ws.mcafee.com0.0.0.0 analytics.ccs.mcafee.com0.0.0.0 analyticsdcs.ccs.mcafee.com0.0.0.0 gate.hockeyapp.net0.0.0.0 api.mixpanel.com0.0.0.0 decide.mixpanel.com0.0.0.0 ads.mopub.com0.0.0.0 incoming.telemetry.mozilla.org0.0.0.0 h.online-metrix.net0.0.0.0 analytics.paddle.com0.0.0.0 treasuredata.com0.0.0.0 in.treasuredata.com0.0.0.0 redshell.io0.0.0.0 api.redshell.io0.0.0.0 carcharodon.trendmicro.com0.0.0.0 cdn.segment.com0.0.0.0 api.segment.io0.0.0.0 mobile-service.segment.com | Entries added to the Windows hosts file by DCRAT |
| Domain / IP address | a0700877.xsph[.]ru141.8.197[.]42 | DCRAT command-and-control infrastructure |
| File name / MD5 | %TEMP%adminapp.exedfdf5e5b78d2ec764c0e5641cf9a0d26 | Mercurial Grabber infostealer binary |
| URL | https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y0M_A86oJHp00O-l8F4jakfVhqFXzMBoy1uBDdj2rBLc | Discord webhook used for stolen-data exfiltration |
| File names / MD5 | %TEMP%gta6.exe, %USERPROFILE%AppDataRoamingsvchost.exeb9648ec8cc806e7661aabcfc91dc836c | Chaos ransomware binaries |
| File name | read_it.txt | Note dropped in folders affected by Chaos ransomware |
| File name / MD5 | %TEMP%YandexPackLoader.exe1ec9eff863dc4418d1498bc3d904899d | Browser installer included in the malicious ISO |
| File name / MD5 | %TEMP%find.vbs0e39e8d7b641bcda4376ebbfeff7b12e | Script that displays the fake “license not found” message |
| Email address | kanalwsegokrytowo555@gmail.com | Address displayed by the fake installer for alleged crack updates |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

