VYPR
breachPublished Sep 10, 2026· 1 source

Fake GTA 6 Download Bundles Malware, Ransomware for Eager Gamers

Cybercriminals are exploiting the immense anticipation for Grand Theft Auto VI by distributing malware-laden ISO files disguised as leaked game downloads.

As Grand Theft Auto VI (GTA 6) remains months away from its official release, threat actors are capitalizing on the fervent anticipation of eager fans. Security researchers at Huntress have uncovered a malicious campaign distributing an ISO file masquerading as a leaked copy of the highly anticipated game. This opportunistic attack bundle is designed to infect users who are tempted to download and install the fake game.

The discovered ISO file contains a deceptive installer, gta6installer.exe, which cleverly uses the icon from GTA 5 to maintain its disguise. Upon execution, the installer presents a Russian-language message, warning of a potential "License not found" error and providing an email address for support. This serves as a plausible excuse for the game not launching, while the actual malicious payload is installed silently in the background.

Analysis of the ISO revealed a collection of malware components, many of which appear to be repurposed older tools dating back to 2023. Once the fake installation process is initiated, several files are dropped into the system's temporary folder, often branded with GTA 6 imagery to avoid raising suspicion. A batch file, checkinternetconnection.bat, then launches Microsoft Edge to confirm an internet connection before proceeding with the deployment of the various malware components.

The payload includes multiple instances of NJRAT and DCRAT, both potent Remote Access Trojans (RATs). NJRAT provides attackers with extensive control, including shell access, keystroke logging, camera hijacking, credential theft, file manipulation, and live desktop viewing. DCRAT complements this with mouse control, screenshot capture, clipboard access, and the ability to modify the Windows hosts file to disrupt security software telemetry.

Further complicating the infection, the bundle contains Mercurial Grabber, an infostealer readily available on GitHub. This tool is designed to exfiltrate sensitive data such as Discord tokens, Chrome passwords and cookies, Roblox and Minecraft session data, Windows product keys, and screenshots, transmitting them via Discord webhooks.

The most destructive element is a variant of Chaos ransomware. However, instead of demanding a ransom, this variant appears to function as a wiper. It encrypts files up to 200MB and overwrites larger files with random data, effectively destroying them. The attackers also delete Shadow copy backups, disable Windows recovery options, and replace the desktop wallpaper with an image of SpongeBob, accompanied by a ransom note from the "ASHA Hacker Team" claiming responsibility.

Interestingly, the installer also drops a copy of Yandex Browser, and the consistent use of Russian-language messaging suggests that Russian-speaking users may be a primary target demographic. Despite the sophisticated multi-stage attack, Huntress notes that an up-to-date version of Windows Defender is capable of detecting and blocking the malware within this particular ISO, as the components are not novel.

This incident serves as a stark reminder that downloading cracked or pirated software, especially for unreleased titles, is a high-risk activity that frequently leads to malware infections. Threat actors actively prey on the impatience and eagerness of gamers, making such unofficial downloads a fertile ground for scams and cyberattacks.

Synthesized by Vypr AI