Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Microsoft Teams Flaw Lets Attackers Create In-Browser Phishing Pages
September 11, 2026
Fake GTA 6 Downloads Deliver RATs, Infostealers, and Wipers
September 11, 2026
Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access
September 10, 2026
Home/Threats/Fake GTA 6 Downloads Deliver RATs, Infostealers, and Wipers
Threats

Fake GTA 6 Downloads Deliver RATs, Infostealers, and Wipers

Key Takeaways Cybercriminals are distributing fake Grand Theft Auto VI downloads that install multiple malware strains. The malicious packages include remote access Trojans (RATs), information...

Sarah simpson
Sarah simpson
September 11, 2026 5 Min Read
2 0

Key Takeaways

  • Cybercriminals are distributing fake Grand Theft Auto VI downloads that install multiple malware strains.
  • The malicious packages include remote access Trojans (RATs), information stealers, and data-wiping ransomware.
  • The campaign targets eager gamers searching for early access, leaked copies, or unofficial demos of the highly anticipated game.
  • The ransomware component acts as a wiper, making files unrecoverable rather than offering a genuine decryption path.

Overview: Fake GTA 6 Downloads Deliver Multiple Threats

Cybercriminals are capitalizing on the immense anticipation surrounding Grand Theft Auto VI by circulating fraudulent game downloads. Instead of providing access to the highly sought-after title, these malicious packages infect victims with a dangerous cocktail of malware, including remote access tools, information stealers, and data-wiping ransomware. The campaign specifically targets individuals seeking early builds, leaked versions, or unofficial demos ahead of the game’s official release.

Table Of Content

  • Key Takeaways
  • Overview: Fake GTA 6 Downloads Deliver Multiple Threats
  • Infection Chain and Malware Payload
  • Ransomware Used as a Wiper
  • Indicators of Compromise (IoCs):-
  • What You Should Do

These deceptive downloads are propagated through various channels, such as manipulated search engine results, gaming forums, torrent sites, and social media platforms. Some of the fake ISO files boast sizes exceeding 100GB, a deliberate tactic to enhance their credibility, with much of the volume comprising inert junk data.

Analysts at Huntress said in a report that they identified a sample combining remote-access malware, an information stealer, file-destroying ransomware, and an additional web browser within a single malicious package. The presence of Russian-language prompts and a Russian ransom note suggests that this operation might primarily target Russian-speaking gaming communities, as detailed in a report.

This incident underscores how highly anticipated game releases can become a significant vector for device compromise, mirroring past campaigns that exploited player eagerness with fake GTA 6 demos.

Infection Chain and Malware Payload

The infection process commences when a user mounts the fraudulent game image and executes what appears to be an installer. The main executable uses an outdated GTA 5-style icon and initially displays a Russian message, falsely claiming that the “leaked” game might not run due to an invalid crack. This message is a deceptive ploy. Upon completion of the “installation,” victims encounter a “license not found” error, providing a plausible, albeit false, explanation for the game’s failure to launch, while the malicious payloads silently deploy in the background.

This calculated delay in revealing the malware’s true nature allows the attackers more time for their payloads to execute. The package drops several files into the Windows temporary directory and verifies internet connectivity before proceeding with further stages of the attack.

The attackers then install multiple instances of NJRAT, a versatile remote-access Trojan. NJRAT grants attackers extensive control over the compromised system, enabling them to log keystrokes, capture screenshots, access webcams, browse files, exfiltrate browser data, and remotely manipulate the operating system.

Additionally, the campaign deploys DCRAT, another remote-access tool. DCRAT’s capabilities include monitoring active windows, capturing clipboard contents, discovering audio devices, and modifying registry settings. Notably, DCRAT alters the Windows hosts file to block specific telemetry and security-reporting services, a tactic designed to reduce the likelihood of the infection being detected or reported.

A separate component, Mercurial Grabber, focuses on data exfiltration. It systematically collects browser passwords and cookies, chat-platform tokens, game-related session data, screenshots, detailed system information, location data, and Windows product keys. This campaign exemplifies the broader threat posed by SEO-poisoned download campaigns, where seemingly legitimate search results direct users to weaponized installers.

Ransomware Used as a Wiper

The most destructive element of this malicious package is Chaos ransomware. However, the attackers do not appear to be interested in extorting payments. Instead, the malware functions as a wiper, encrypting smaller files and overwriting files larger than 200MB with random data, rendering them effectively unrecoverable.

If the compromised user possesses administrator privileges, the malware takes additional steps to ensure data destruction. It deletes shadow copies and disables system recovery options before initiating the file destruction process. The ransomware targets critical personal folders, shared data locations, saved game files, and cloud-synchronized storage, leading to potentially devastating data loss that can extend beyond the infected device itself.

The ransomware leaves behind a ransom note asserting that files are “encrypted forever,” rather than providing a legitimate path to recovery. This behavior makes the campaign particularly dangerous for gamers, who might anticipate only password theft but instead face the permanent loss of documents, photos, game saves, and locally stored work files.

Indicators of Compromise (IoCs):-

Type Indicator Description
File name / MD5 Gta6installer.exe
a15e280a3fd65dfaa243bbe2dbf45e97
Initial fake installation executable
File name / MD5 %TEMP%checkinternetconnection.bat
6b49f24d5d5b49127476bc385565f8b0
Batch file used to confirm internet connectivity
File names / MD5s %TEMP%licensechecker.exe, %TEMP%rockstar.exe, %TEMP%steam.exe, %TEMP%any.ran.exe, %TEMP%svchost.exe, %TEMP%abc.exe, %TEMP%license.exe, %TEMP%rockstargamescrashfixer.exe, %TEMP%rockstarservices.exe
2a0834560ed3770fc33d7a42f8229722
57b9c56ef97a7ada98257b23577bf5e3
60a0f58001ea7be538cd42b651924cc7
15eca4a3f7350423cf4db0b4c30d1968
ea991bc9334b36a6b958f564ee716776
2a385fe7bed9899d77d05cb8e302d557
NJRAT copies and associated launchers
IP addresses 35.157.111[.]131
3.68.56[.]232
3.67.15[.]169
Infrastructure contacted by NJRAT
Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT
File names / MD5 %TEMP%rockstargames.exe, %TEMP%P3usMXh1h4.bat, C:UsersDefaultLocal Settings[RANDOM FILE NAME].exe
8da3fe3664d81226b0fb2a50a0537d4f
DCRAT installer components and binary
Hosts-file entries 0.0.0.0 app.adjust.com
0.0.0.0 app.adjust.io
0.0.0.0 app-sj01.marketo.com
0.0.0.0 t.appsflyer.com
0.0.0.0 analytics.ff.avast.com
0.0.0.0 analytics.ns1.ff.avast.com
0.0.0.0 v7event.stats.avcdn.net
0.0.0.0 v7.stats.avcdn.net
0.0.0.0 ads.avocet.io
0.0.0.0 telemetry.battle.net
0.0.0.0 analytics.rollout.io
0.0.0.0 metrics.ol.epicgames.com
0.0.0.0 a.fiksu.com
0.0.0.0 sdk.fiksu.com
0.0.0.0 settings.crashlytics.com
0.0.0.0 e.crashlytics.com
0.0.0.0 insights-collector.gog.com
0.0.0.0 ssl.google-analytics.com
0.0.0.0 ssl-google-analytics.l.google.com
0.0.0.0 static.hotjar.com
0.0.0.0 flow.lavasoft.com
0.0.0.0 telemetry.servers.getgo.com
0.0.0.0 telemetry.malwarebytes.com
0.0.0.0 ws.mcafee.com
0.0.0.0 analytics.ccs.mcafee.com
0.0.0.0 analyticsdcs.ccs.mcafee.com
0.0.0.0 gate.hockeyapp.net
0.0.0.0 api.mixpanel.com
0.0.0.0 decide.mixpanel.com
0.0.0.0 ads.mopub.com
0.0.0.0 incoming.telemetry.mozilla.org
0.0.0.0 h.online-metrix.net
0.0.0.0 analytics.paddle.com
0.0.0.0 treasuredata.com
0.0.0.0 in.treasuredata.com
0.0.0.0 redshell.io
0.0.0.0 api.redshell.io
0.0.0.0 carcharodon.trendmicro.com
0.0.0.0 cdn.segment.com
0.0.0.0 api.segment.io
0.0.0.0 mobile-service.segment.com
Entries added to the Windows hosts file by DCRAT
Domain / IP address a0700877.xsph[.]ru
141.8.197[.]42
DCRAT command-and-control infrastructure
File name / MD5 %TEMP%adminapp.exe
dfdf5e5b78d2ec764c0e5641cf9a0d26
Mercurial Grabber infostealer binary
URL https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y0M_A86oJHp00O-l8F4jakfVhqFXzMBoy1uBDdj2rBLc Discord webhook used for stolen-data exfiltration
File names / MD5 %TEMP%gta6.exe, %USERPROFILE%AppDataRoamingsvchost.exe
b9648ec8cc806e7661aabcfc91dc836c
Chaos ransomware binaries
File name read_it.txt Note dropped in folders affected by Chaos ransomware
File name / MD5 %TEMP%YandexPackLoader.exe
1ec9eff863dc4418d1498bc3d904899d
Browser installer included in the malicious ISO
File name / MD5 %TEMP%find.vbs
0e39e8d7b641bcda4376ebbfeff7b12e
Script that displays the fake “license not found” message
Email address [email protected] Address displayed by the fake installer for alleged crack updates

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

What You Should Do

  • Avoid Unofficial Downloads: Always download games, especially highly anticipated titles, exclusively from official publisher websites, verified digital storefronts (like Steam, Epic Games Store, PlayStation Store, Xbox Store), or trusted platform channels. Never trust alleged “leaked builds,” torrent listings, or social media posts promising early access.
  • Be Skeptical of Search Results: Exercise caution with download links from unfamiliar search results, as these can be manipulated through SEO poisoning to lead to malicious installers.
  • Isolate Infected Devices: If you suspect you have run a malicious GTA 6 installer, immediately disconnect the affected device from all networks (Wi-Fi and Ethernet) to prevent further compromise or spread of malware.
  • Change Passwords: From a clean, uncompromised device, change all passwords for accounts that may have been accessed on the infected machine

    Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

    Tags:

    AttackExploitMalwareransomwareSecurityThreat

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Cisco ASA, FTD Critical Flaw CVE-2024-20353 Lets Attackers Gain Root Access

Next Post

Critical Microsoft Teams Flaw Lets Attackers Create In-Browser Phishing Pages

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Attack Steals Data via AI Workflows, No Jailbreak Needed
September 10, 2026
Critical LiteLLM Flaws Let Attackers Execute Code as Root, Steal Cloud Credentials
September 10, 2026
Palo Alto PAN-OS Critical Vulnerability Lets Attackers Execute Code as Root
September 10, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us