HomeCyber BalkansFake GTA6 Leaked Download Spreads RATs, Infostealer, and Wiper Ransomware

Fake GTA6 Leaked Download Spreads RATs, Infostealer, and Wiper Ransomware

Published on

spot_img

Unveiling the Threat: Cybersecurity Firm Identifies Malware Targeting Anticipation for GTA VI

In a revealing discovery, cybersecurity firm Huntress has exposed a sophisticated malware campaign that exploits the heightened anticipation surrounding the forthcoming release of Grand Theft Auto VI (GTA VI). This malicious scheme cleverly disguises itself within deceptive “leaked” copies of the eagerly awaited game, incorporating various forms of malware, including remote access trojans, an infostealer, and destructive ransomware.

Despite the game’s official release being three months away, the overwhelming excitement among fans has been intensified by recent leaks of gameplay footage and an official teaser from the game’s publisher, Rockstar Games. This buzz has swiftly drawn the attention of threat actors, who have initiated a campaign to capitalize on the situation by inundating search results, gaming forums, social media platforms, and torrent sites with counterfeit disc image files (ISOs) that falsely promise early access to the game. According to Huntress, it is important to note that no authentic, playable version of GTA VI is currently available.

The Deceptive Installer

Some of the fabricated ISOs that have surfaced are alarmingly large, some exceeding 100GB. Huntress discovered that these files are artificially inflated with redundant data to imitate the size of a legitimate AAA game release. The genuine payload of malware hidden within these ISOs is considerably smaller but is designed to be a broad-spectrum attack, aiming to ensnare any unsuspecting users who opt to run the installer.

When victims open the ISO, they are confronted with an executable file labeled gta6installer.exe, curiously depicted with an icon associated with GTA V instead of the anticipated GTA VI. Upon running this installer, users encounter a warning in Russian that the game is unlicensed and may not operate as intended. It instructs users to email the attackers if they face a “License not found” error, supposedly to fix the issue. This scripted message is a strategic diversion that ultimately masks the fact that the game does not exist, while enabling the silent installation of malware in the background.

An Arsenal of Malware

Delving deeper into the inner workings of this elaborate scheme, Huntress cataloged an unsettling array of malware embedded within the fake installer. Much of this malware, though not particularly new, has been repurposed for this campaign. The research revealed multiple instances of a remote access trojan known as NJRAT, along with another variant called DCRAT. These tools empower attackers to log keystrokes, access victims’ webcams, navigate through desktops, pilfer browser credentials, and cryptocurrency wallet information, thus gaining full control over compromised systems.

Additionally, the installation includes a notorious open-source infostealer dubbed Mercurial Grabber, marketed as an educational tool. This component is designed to harvest sensitive information such as Discord tokens, saved passwords from Chrome, session data from popular gaming platforms like Roblox and Minecraft, as well as Windows product keys and system details. All this sensitive information is exfiltrated through a Discord webhook, adding another layer of risk for affected users.

Even more concerning is the presence of a variant of the well-known Chaos ransomware family. Huntress indicates that this ransomware is employed primarily as a wiper, rather than for traditional financial extortion. Once activated on a machine with administrative rights, it obliterates shadow copy backups, deactivates Windows recovery options, and either encrypts files smaller than 200MB or outright overwrites larger files with random data, resulting in irreversible data loss. The ransomware specifically targets folders containing documents, images, and files stored on OneDrive, and, notably, alters the desktop wallpaper to display an image of SpongeBob SquarePants alongside a message proclaiming the device has been compromised by the "Asha Hacker Team," complete with a ransom note that deceptively provides no payment mechanism.

Targeting the Vulnerable

Moreover, the installer further installs Yandex Browser, a service highly regarded in Russia and Eastern Europe. Given the Russian-language prompts and ransom messages, Huntress infers that the primary target of this malware campaign consists of Russian-speaking gamers; however, the tactics employed could easily be adapted to ensnare unsuspecting fans in other regions as well.

Huntress emphasizes that the individual components of the malware, while concerning, do not present an advanced level of sophistication. An updated version of Windows Defender should be capable of detecting and blocking these threats. The real danger lies in the social engineering tactics employed; eager fans, desperate to get their hands on a coveted early copy of a major game release, may be more inclined to disregard security warnings and proceed with executing unverified files.

The cybersecurity firm offers straightforward advice: refrain from downloading pirated or cracked software, especially for titles that have yet to be officially launched. For those who suspect they have unwittingly installed this bogus software, it is crucial to disconnect the compromised device from the internet immediately, reset passwords, enable two-factor authentication where available, and reformat the system rather than attempting to clean it.

As part of their efforts to combat this evolving threat landscape, Huntress has published comprehensive technical indicators of compromise, including file hashes, dropped file paths, and command-and-control infrastructure, all accompanying its detailed analysis.

For further information and insights, Huntress’s full report can be accessed online.

Source link

Latest articles

FBI Strategy Promotes Increased Takedowns and Improved Information Sharing

Cybercrime, Fraud Management & Cybercrime, ...

Gigabud Employs Android App Cloning to Avoid Fraud Detection

The Rise of the Gigabud Android Banking Trojan: A New Threat to Financial Security The...

Boston Scientific Warns of Financial Impact Due to Cyberattack

Boston Scientific Faces Significant Financial Impact from Recent Cyberattack In a noteworthy development, medical device...

Cyber Briefing – September 9, 2026 – CyberMaterial

Cybersecurity Briefing: Major Threats and Vulnerabilities in Current Digital Landscape In a landscape increasingly characterized...

More like this

FBI Strategy Promotes Increased Takedowns and Improved Information Sharing

Cybercrime, Fraud Management & Cybercrime, ...

Gigabud Employs Android App Cloning to Avoid Fraud Detection

The Rise of the Gigabud Android Banking Trojan: A New Threat to Financial Security The...

Boston Scientific Warns of Financial Impact Due to Cyberattack

Boston Scientific Faces Significant Financial Impact from Recent Cyberattack In a noteworthy development, medical device...