Fake GTA 6 Downloads Deliver RATs, Infostealers, and Wipers
Key Takeaways Cybercriminals are distributing fake Grand Theft Auto VI downloads that install multiple malware strains. The malicious packages include remote access Trojans (RATs), information...
Key Takeaways
- Cybercriminals are distributing fake Grand Theft Auto VI downloads that install multiple malware strains.
- The malicious packages include remote access Trojans (RATs), information stealers, and data-wiping ransomware.
- The campaign targets eager gamers searching for early access, leaked copies, or unofficial demos of the highly anticipated game.
- The ransomware component acts as a wiper, making files unrecoverable rather than offering a genuine decryption path.
Overview: Fake GTA 6 Downloads Deliver Multiple Threats
Cybercriminals are capitalizing on the immense anticipation surrounding Grand Theft Auto VI by circulating fraudulent game downloads. Instead of providing access to the highly sought-after title, these malicious packages infect victims with a dangerous cocktail of malware, including remote access tools, information stealers, and data-wiping ransomware. The campaign specifically targets individuals seeking early builds, leaked versions, or unofficial demos ahead of the game’s official release.
Table Of Content
These deceptive downloads are propagated through various channels, such as manipulated search engine results, gaming forums, torrent sites, and social media platforms. Some of the fake ISO files boast sizes exceeding 100GB, a deliberate tactic to enhance their credibility, with much of the volume comprising inert junk data.
Analysts at Huntress said in a report that they identified a sample combining remote-access malware, an information stealer, file-destroying ransomware, and an additional web browser within a single malicious package. The presence of Russian-language prompts and a Russian ransom note suggests that this operation might primarily target Russian-speaking gaming communities, as detailed in a report.
This incident underscores how highly anticipated game releases can become a significant vector for device compromise, mirroring past campaigns that exploited player eagerness with fake GTA 6 demos.
Infection Chain and Malware Payload
The infection process commences when a user mounts the fraudulent game image and executes what appears to be an installer. The main executable uses an outdated GTA 5-style icon and initially displays a Russian message, falsely claiming that the “leaked” game might not run due to an invalid crack. This message is a deceptive ploy. Upon completion of the “installation,” victims encounter a “license not found” error, providing a plausible, albeit false, explanation for the game’s failure to launch, while the malicious payloads silently deploy in the background.
This calculated delay in revealing the malware’s true nature allows the attackers more time for their payloads to execute. The package drops several files into the Windows temporary directory and verifies internet connectivity before proceeding with further stages of the attack.
The attackers then install multiple instances of NJRAT, a versatile remote-access Trojan. NJRAT grants attackers extensive control over the compromised system, enabling them to log keystrokes, capture screenshots, access webcams, browse files, exfiltrate browser data, and remotely manipulate the operating system.
Additionally, the campaign deploys DCRAT, another remote-access tool. DCRAT’s capabilities include monitoring active windows, capturing clipboard contents, discovering audio devices, and modifying registry settings. Notably, DCRAT alters the Windows hosts file to block specific telemetry and security-reporting services, a tactic designed to reduce the likelihood of the infection being detected or reported.
A separate component, Mercurial Grabber, focuses on data exfiltration. It systematically collects browser passwords and cookies, chat-platform tokens, game-related session data, screenshots, detailed system information, location data, and Windows product keys. This campaign exemplifies the broader threat posed by SEO-poisoned download campaigns, where seemingly legitimate search results direct users to weaponized installers.
Ransomware Used as a Wiper
The most destructive element of this malicious package is Chaos ransomware. However, the attackers do not appear to be interested in extorting payments. Instead, the malware functions as a wiper, encrypting smaller files and overwriting files larger than 200MB with random data, rendering them effectively unrecoverable.
If the compromised user possesses administrator privileges, the malware takes additional steps to ensure data destruction. It deletes shadow copies and disables system recovery options before initiating the file destruction process. The ransomware targets critical personal folders, shared data locations, saved game files, and cloud-synchronized storage, leading to potentially devastating data loss that can extend beyond the infected device itself.
The ransomware leaves behind a ransom note asserting that files are “encrypted forever,” rather than providing a legitimate path to recovery. This behavior makes the campaign particularly dangerous for gamers, who might anticipate only password theft but instead face the permanent loss of documents, photos, game saves, and locally stored work files.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| File name / MD5 | Gta6installer.exea15e280a3fd65dfaa243bbe2dbf45e97 |
Initial fake installation executable |
| File name / MD5 | %TEMP%checkinternetconnection.bat6b49f24d5d5b49127476bc385565f8b0 |
Batch file used to confirm internet connectivity |
| File names / MD5s | %TEMP%licensechecker.exe, %TEMP%rockstar.exe, %TEMP%steam.exe, %TEMP%any.ran.exe, %TEMP%svchost.exe, %TEMP%abc.exe, %TEMP%license.exe, %TEMP%rockstargamescrashfixer.exe, %TEMP%rockstarservices.exe2a0834560ed3770fc33d7a42f822972257b9c56ef97a7ada98257b23577bf5e360a0f58001ea7be538cd42b651924cc715eca4a3f7350423cf4db0b4c30d1968ea991bc9334b36a6b958f564ee7167762a385fe7bed9899d77d05cb8e302d557 |
NJRAT copies and associated launchers |
| IP addresses | 35.157.111[.]1313.68.56[.]2323.67.15[.]169 |
Infrastructure contacted by NJRAT |
| Domain / Port | 7.tcp.eu.ngrok[.]io:12684 |
ngrok endpoint contacted by NJRAT |
| File names / MD5 | %TEMP%rockstargames.exe, %TEMP%P3usMXh1h4.bat, C:UsersDefaultLocal Settings[RANDOM FILE NAME].exe8da3fe3664d81226b0fb2a50a0537d4f |
DCRAT installer components and binary |
| Hosts-file entries | 0.0.0.0 app.adjust.com0.0.0.0 app.adjust.io0.0.0.0 app-sj01.marketo.com0.0.0.0 t.appsflyer.com0.0.0.0 analytics.ff.avast.com0.0.0.0 analytics.ns1.ff.avast.com0.0.0.0 v7event.stats.avcdn.net0.0.0.0 v7.stats.avcdn.net0.0.0.0 ads.avocet.io0.0.0.0 telemetry.battle.net0.0.0.0 analytics.rollout.io0.0.0.0 metrics.ol.epicgames.com0.0.0.0 a.fiksu.com0.0.0.0 sdk.fiksu.com0.0.0.0 settings.crashlytics.com0.0.0.0 e.crashlytics.com0.0.0.0 insights-collector.gog.com0.0.0.0 ssl.google-analytics.com0.0.0.0 ssl-google-analytics.l.google.com0.0.0.0 static.hotjar.com0.0.0.0 flow.lavasoft.com0.0.0.0 telemetry.servers.getgo.com0.0.0.0 telemetry.malwarebytes.com0.0.0.0 ws.mcafee.com0.0.0.0 analytics.ccs.mcafee.com0.0.0.0 analyticsdcs.ccs.mcafee.com0.0.0.0 gate.hockeyapp.net0.0.0.0 api.mixpanel.com0.0.0.0 decide.mixpanel.com0.0.0.0 ads.mopub.com0.0.0.0 incoming.telemetry.mozilla.org0.0.0.0 h.online-metrix.net0.0.0.0 analytics.paddle.com0.0.0.0 treasuredata.com0.0.0.0 in.treasuredata.com0.0.0.0 redshell.io0.0.0.0 api.redshell.io0.0.0.0 carcharodon.trendmicro.com0.0.0.0 cdn.segment.com0.0.0.0 api.segment.io0.0.0.0 mobile-service.segment.com |
Entries added to the Windows hosts file by DCRAT |
| Domain / IP address | a0700877.xsph[.]ru141.8.197[.]42 |
DCRAT command-and-control infrastructure |
| File name / MD5 | %TEMP%adminapp.exedfdf5e5b78d2ec764c0e5641cf9a0d26 |
Mercurial Grabber infostealer binary |
| URL | https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y0M_A86oJHp00O-l8F4jakfVhqFXzMBoy1uBDdj2rBLc |
Discord webhook used for stolen-data exfiltration |
| File names / MD5 | %TEMP%gta6.exe, %USERPROFILE%AppDataRoamingsvchost.exeb9648ec8cc806e7661aabcfc91dc836c |
Chaos ransomware binaries |
| File name | read_it.txt |
Note dropped in folders affected by Chaos ransomware |
| File name / MD5 | %TEMP%YandexPackLoader.exe1ec9eff863dc4418d1498bc3d904899d |
Browser installer included in the malicious ISO |
| File name / MD5 | %TEMP%find.vbs0e39e8d7b641bcda4376ebbfeff7b12e |
Script that displays the fake “license not found” message |
| Email address | [email protected] |
Address displayed by the fake installer for alleged crack updates |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
What You Should Do
- Avoid Unofficial Downloads: Always download games, especially highly anticipated titles, exclusively from official publisher websites, verified digital storefronts (like Steam, Epic Games Store, PlayStation Store, Xbox Store), or trusted platform channels. Never trust alleged “leaked builds,” torrent listings, or social media posts promising early access.
- Be Skeptical of Search Results: Exercise caution with download links from unfamiliar search results, as these can be manipulated through SEO poisoning to lead to malicious installers.
- Isolate Infected Devices: If you suspect you have run a malicious GTA 6 installer, immediately disconnect the affected device from all networks (Wi-Fi and Ethernet) to prevent further compromise or spread of malware.
- Change Passwords: From a clean, uncompromised device, change all passwords for accounts that may have been accessed on the infected machine
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.