ZeroHour
Help Net Securitypublished ()ingested Sinisa Markovic1
Part of a story covered by 4 sources: “Fake GTA 6 'leaked build' ISOs deliver NJRAT, DCRAT, Mercurial Grabber, and Chaos ransomware wiper” — merged summary and timeline →

Fake GTA 6 download delivers malware-packed bundle to impatient gamers

mediumMalware exploited in the wildimportance 45
AI summary · glm-5.3-flash

Huntress found malware disguised as a leaked GTA 6 download bundling NJRAT, DCRAT, an infostealer, and Chaos ransomware used as a wiper.

Huntress analyzed a fake Grand Theft Auto VI ISO whose gta6installer.exe displays a fake 'License not found' error while silently installing payloads. The bundle includes NJRAT and DCRAT remote access trojans, the Mercurial Grabber infostealer, and a Chaos ransomware variant used destructively as a wiper, plus a Yandex Browser drop. The Chaos variant encrypts files up to 200MB, overwrites larger ones, deletes shadow copies, and disables recovery, with no ransom actually demanded. Most components are old malware dating to 2023 and are detected by up-to-date Windows Defender.

  • Fake gta6installer.exe shows a 'License not found' error while silently installing payloads.
  • Bundle includes NJRAT, DCRAT, Mercurial Grabber, and a Chaos ransomware variant.
  • Chaos encrypts files up to 200MB and destroys larger ones, deleting shadow copies.
  • Components date to 2023; up-to-date Windows Defender detects them.

Indicators of compromiseAll →

TypeIndicatorContext
domainclck.rut file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp, where it confirms that it has an internet connect
Full article685 words · extracted from helpnetsecurity.com · click to collapse

Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their hands on it early.

The sample Huntress pulled apart contained several different malware components. Researchers described an opportunistic bundle, “throwing everything they can at the users who attempt an installation,” a package that includes a fake installer, several RATs, an infostealer, ransomware used as a wiper, and a web browser.

A fake installer hides the payload

Opening the ISO presents the main installer file, gta6installer.exe, still carrying the icon from GTA5. Running it displays a message in Russian, warning that the installation may fail with a “License not found” error and offering an email address to request a fix.

Fake GTA 6 malware

Message contained within the fake GTA6 installer (Source: Huntress)

Once the install finishes, a script fires and shows exactly that error message, giving the user a plausible reason why the game never launched. While that plays out, the actual payload installs in the background.

Huntress contacted the email address listed in the installer to see who would respond, but didn’t receive a response at the time of writing.

“The malware contained within the ISO appears to be fairly old, repurposed for this opportunistic attack, with files dating back to 2023 in many cases. Proceeding with the installation, several files are added to the %TEMP% folder on the system, many of which appear to be GTA6-branded to avoid suspicion,” researchers wrote.

“The checkinternetconnection.bat file then launches Microsoft Edge and connects to https://clck[.]ru/34uJnp, where it confirms that it has an internet connection before proceeding to unpack and install the various malware components.”

RATs, an infostealer, and destructive ransomware

Multiple copies of NJRAT show up first, giving an attacker a shell, keystroke logging, camera access, browser credential theft, file upload and download, control over files and registry entries, live desktop viewing and screenshots, and access to cryptocurrency wallet details.

Alongside it comes a copy of DCRAT, which gives an attacker mouse control, screenshot capture, clipboard access, registry read and write permissions, audio device discovery, and window tracking. DCRAT also rewrites the Windows hosts file to block antivirus telemetry from reaching security vendors.

Then there’s an infostealer, a tool called Mercurial Grabber that’s freely available on GitHub under an “educational purposes only” label. It collects Discord tokens, Chrome passwords and cookies, Roblox and Minecraft session data, Windows product keys, and screenshots, then sends everything out through a Discord webhook.

The most damaging piece is a Chaos ransomware variant. “While this is technically a well-known ransomware family, it appears that the actors are not looking to collect a ransom from infected users. Instead, they encrypt and/or destroy files on the system, effectively utilizing the ransomware as a wiper,” researchers noted.

It encrypts files 200MB and smaller and overwrites anything larger with random data, destroying it outright. Shadow copy backups are deleted and Windows recovery options disabled, while the desktop wallpaper is changed to an image of SpongeBob paired with a message claiming the hack was carried out by the “ASHA Hacker Team.”

“Hello, your files has been encrypted by achvz1om i don’t have paypal or other banks so you don’t can donate me so, your files has been encrypted forever,” the ransom note reads.

Finally, the installer drops a copy of Yandex Browser, for no apparent reason Huntress could pin down. Combined with the Russian-language messaging throughout, this suggests Russian-speaking users may be among the intended targets.

Windows Defender can detect the malware

The good news, researchers said, is there’s nothing particularly new in this ISO. The malware it contains is several years old, and an up-to-date version of Windows Defender should have no trouble detecting it and stopping it from compromising the system.

“Generally speaking, it’s not a good idea to attempt to download cracked, pirated software, especially if the game in question has not yet been released. This is fertile ground for scams and threat actors attempting to take advantage of the impatient and overeager,” Huntress concluded.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/09/10/fake-gta-6-downloads-malware-ransomware/