Grand Theft Auto VI hype leads to malware
Fake Grand Theft Auto VI game installers are spreading malware to Russian-speaking gamers. Attackers hide RATs, credential stealers, and ransomware in fake game files shared on forums, social media, and torrent sites.
- Report priority
- High
- Targets
- gaming+3 more
How it works
- Attackers create fake Grand Theft Auto VI game installers that look like leaked copies.
- They share these files on gaming forums, social media, and torrent sites.
- When a gamer opens the fake installer, it runs hidden malware that steals passwords, takes control of the computer, and can even delete files.
- The malware also sends stolen data to the attackers.
What to do
Check your %TEMP% folder for suspicious files or unexpected programs. If you see unknown files or programs, do not open them.
Do not open any fake game files, even if they look like leaked copies. Delete any suspicious files you may have downloaded. Run a full scan with your antivirus software to check for malware. If your files are encrypted or you notice unusual behavior, contact your antivirus provider for help.
Technical details
Affected software: gaming, infostealer, seo poisoning, mercurial grabber
A Russian-speaking gamer downloads what they think is a leaked copy of Grand Theft Auto VI from a gaming forum. The fake installer runs and installs malware that steals their login details, takes control of their computer, and encrypts some files as a ransomware attack.
A malicious campaign is exploiting hype around Grand Theft Auto VI by distributing fake game ISOs containing multiple embedded malware payloads. The fake installers, spread via SEO poisoning, gaming forums, social media, and torrent sites, deploy NJRAT, DCRAT (remote access trojans), Mercurial Grabber (infostealer), and Chaos ransomware (functioning as a file wiper) alongside Yandex Browser. Execution drops these components to %TEMP% folders, enabling data exfiltration, credential theft, system control, and destructive file encryption.
The campaign appears targeted at Russian-speaking gamers, as evidenced by Russian-language prompts and infrastructure. The malware components originate from 2023, indicating repurposed tools for this opportunistic attack.