ZeroHour
Cyber Security Newspublished ()ingested Tushar Subhra Dutta
Part of a story covered by 4 sources: “Fake GTA 6 'leaked build' ISOs deliver NJRAT, DCRAT, Mercurial Grabber, and Chaos ransomware wiper” — merged summary and timeline →

Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware

mediumMalware exploited in the wildimportance 45
AI summary · glm-5.3-flash

Huntress tracked fake GTA 6 downloads distributing NJRAT, DCRAT, Mercurial Grabber, and Chaos ransomware used as a wiper against gamers.

Cybercriminals are pushing fake Grand Theft Auto VI downloads through poisoned search results, gaming forums, torrent sites, and social media, targeting players seeking a leaked build before release. Huntress analyzed a sample bundling NJRAT, DCRAT, Mercurial Grabber, and Chaos ransomware in one package; fake ISO files exceed 100GB largely with junk data, and Russian-language prompts suggest the operators target Russian-speaking gamers. Chaos ransomware acts as a wiper, overwriting files larger than 200MB with random data, deleting shadow copies for admin users, and disabling recovery options rather than offering genuine ransom payment paths.

  • Fake installers show a license error while malware runs in background
  • NJRAT and DCRAT provide keylogging, screenshots, webcam, and clipboard access
  • Mercurial Grabber steals passwords, cookies, chat tokens, and product keys
  • Chaos ransomware overwrites files over 200MB, acting as a wiper
  • Hosts file changes block telemetry and security-reporting services

Indicators of compromiseAll →

TypeIndicatorContext
domain7.tcp.eu67.15[.]169 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File nam
domaindiscord.com41cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y
domainflow.lavasoft.comle-analytics.l.google.com 0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwa
domainmobile-service.segment.com.com 0.0.0.0 cdn.segment.com 0.0.0.0 api.segment.io 0.0.0.0 mobile-service.segment.com Entries added to the Windows hosts file by DCRAT Domain / I
domainngrok.io69 Infrastructure contacted by NJRAT Domain / Port 7.tcp.eu.ngrok[.]io:12684 ngrok endpoint contacted by NJRAT File names / MD5
domaintelemetry.servers.getgo.com0.0.0.0 static.hotjar.com 0.0.0.0 flow.lavasoft.com 0.0.0.0 telemetry.servers.getgo.com 0.0.0.0 telemetry.malwarebytes.com 0.0.0.0 ws.mcafee.com 0.
domainxsph.ruhe Windows hosts file by DCRAT Domain / IP address a0700877.xsph[.]ru 141.8.197[.]42 DCRAT command-and-control infrastructure F
md50e39e8d7b641bcda4376ebbfeff7b12ecluded in the malicious ISO File name / MD5 %TEMP%\find.vbs 0e39e8d7b641bcda4376ebbfeff7b12e Script that displays the fake “license not found” message E
md515eca4a3f7350423cf4db0b4c30d19686ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e3
md51ec9eff863dc4418d1498bc3d904899dhaos ransomware File name / MD5 %TEMP%\YandexPackLoader.exe 1ec9eff863dc4418d1498bc3d904899d Browser installer included in the malicious ISO File name /
md52a0834560ed3770fc33d7a42f8229722%\rockstargamescrashfixer.exe , %TEMP%\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651
md52a385fe7bed9899d77d05cb8e302d557a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associated launchers IP addresses 35.157.1
md557b9c56ef97a7ada98257b23577bf5e3TEMP%\rockstarservices.exe 2a0834560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c3
md560a0f58001ea7be538cd42b651924cc7560ed3770fc33d7a42f8229722 57b9c56ef97a7ada98257b23577bf5e3 60a0f58001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee
md56b49f24d5d5b49127476bc385565f8b0ecutable File name / MD5 %TEMP%\checkinternetconnection.bat 6b49f24d5d5b49127476bc385565f8b0 Batch file used to confirm internet connectivity File names
md58da3fe3664d81226b0fb2a50a0537d4fat , C:\Users\Default\Local Settings\[RANDOM FILE NAME].exe 8da3fe3664d81226b0fb2a50a0537d4f DCRAT installer components and binary Hosts-file entries 0.
md5a15e280a3fd65dfaa243bbe2dbf45e97ype Indicator Description File name / MD5 Gta6installer.exe a15e280a3fd65dfaa243bbe2dbf45e97 Initial fake installation executable File name / MD5 %TEMP%
md5b9648ec8cc806e7661aabcfc91dc836c%TEMP%\gta6.exe , %USERPROFILE%\AppData\Roaming\svchost.exe b9648ec8cc806e7661aabcfc91dc836c Chaos ransomware binaries File name read_it.txt Note droppe
md5dfdf5e5b78d2ec764c0e5641cf9a0d26-control infrastructure File name / MD5 %TEMP%\adminapp.exe dfdf5e5b78d2ec764c0e5641cf9a0d26 Mercurial Grabber infostealer binary URL https://discord[.]
md5ea991bc9334b36a6b958f564ee7167768001ea7be538cd42b651924cc7 15eca4a3f7350423cf4db0b4c30d1968 ea991bc9334b36a6b958f564ee716776 2a385fe7bed9899d77d05cb8e302d557 NJRAT copies and associate
Full article1,098 words · extracted from cybersecuritynews.com · click to collapse

Cybercriminals are exploiting intense interest in Grand Theft Auto VI by pushing fake game downloads that install several types of malware instead of a playable game. The campaign targets people looking for an early build, leaked copy, or unofficial demo before the title’s release.

The malicious downloads are distributed through poisoned search results, gaming forums, torrent sites, and social-media posts. Some of the fake ISO files exceed 100GB, but the large size is mainly junk data intended to make the download appear believable.

Analysts at Huntress identified a sample that combined remote-access malware, an information stealer, file-destroying ransomware, and an extra web browser in one package.

The use of Russian-language prompts and a Russian ransom note suggests the operation may be aimed primarily at Russian-speaking gamers.

Huntress said in a report shared with Cyber Security News (CSN) that the campaign abuses the absence of any legitimate GTA 6 demo or leaked playable build.

Icon for the main installer file (Source - Huntress)
Icon for the main installer file (Source – Huntress)

The case shows how a high-profile game release can turn ordinary searches into a route for device compromise, similar to earlier fake GTA 6 demo malware activity targeting eager players.

Fake GTA 6 Downloads Deliver Multiple Threats

The infection begins when a victim mounts the fake game image and launches what appears to be an installer. The main program uses an older GTA 5-style icon, then displays a Russian message warning that the supposed leaked game may fail because its crack is no longer valid.

That warning is part of the deception. Once the installation finishes, victims see a “license not found” error, giving them a believable reason why the game did not open while malware runs quietly in the background.

This approach helps attackers delay suspicion and gives their payloads more time to operate. The package drops several files into the Windows temporary folder and checks whether the device can reach the internet before continuing.

It then installs multiple copies of NJRAT, a remote-access tool that can let an attacker record keystrokes, capture screenshots, access webcams, browse files, steal browser data, and remotely control the system.

Message contained within the fake GTA6 installer (Source - Huntress)
Message contained within the fake GTA6 installer (Source – Huntress)

The attackers also deploy DCRAT, another remote-access tool that can monitor windows, capture the clipboard, discover audio devices, and change registry settings.

It changes the Windows hosts file to block selected telemetry and security-reporting services, a tactic that may reduce the chance of the infection being noticed or reported.

A separate component, Mercurial Grabber, collects browser passwords and cookies, chat-platform tokens, game-related session data, screenshots, system details, location information, and Windows product keys.

The campaign reflects the same broad risk seen in SEO poisoned download campaigns, where trusted-looking search results lead users to weaponized installers.

Ransomware Used as a Wiper

The most damaging part of the package is Chaos ransomware, although the operators do not appear interested in collecting payment.

Instead, the malware acts like a wiper by encrypting smaller files and overwriting files larger than 200MB with random data, making them effectively unrecoverable.

If the infected user has administrator rights, the malware deletes shadow copies and disables recovery options before starting file destruction.

It targets common personal folders, shared data locations, saved games, and cloud-synchronised storage, creating a damaging outcome that can extend beyond the device itself.

Error message (Source - Huntress)
Error message (Source – Huntress)

The ransomware leaves a note claiming files have been encrypted forever, rather than giving victims a genuine recovery path.

That behavior makes the campaign especially dangerous for gamers who may expect only password theft but instead lose documents, photos, game saves, and locally stored work files.

Users should avoid alleged unreleased games, pirated installers, and download pages promoted through unfamiliar search results.

Search-result manipulation remains a recurring delivery method, as shown by malicious software search results that imitate legitimate download sources to lure Windows users.

Anyone who ran a suspected GTA 6 installer should immediately disconnect the device from the network, reset passwords from a clean device, enable two-factor authentication, and perform a full system reinstallation.

Keeping security protections updated can also help detect the older malware families used in this operation. The campaign is a reminder that popular games create a ready-made social-engineering opportunity.

Players should wait for announcements and downloads from official publisher channels, rather than trusting leaked-build claims, torrent listings, or posts promising early access.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
File name / MD5Gta6installer.exe
a15e280a3fd65dfaa243bbe2dbf45e97
Initial fake installation executable
File name / MD5%TEMP%\checkinternetconnection.bat
6b49f24d5d5b49127476bc385565f8b0
Batch file used to confirm internet connectivity
File names / MD5s%TEMP%\licensechecker.exe%TEMP%\rockstar.exe%TEMP%\steam.exe%TEMP%\any.ran.exe%TEMP%\svchost.exe%TEMP%\abc.exe%TEMP%\license.exe%TEMP%\rockstargamescrashfixer.exe%TEMP%\rockstarservices.exe
2a0834560ed3770fc33d7a42f8229722
57b9c56ef97a7ada98257b23577bf5e3
60a0f58001ea7be538cd42b651924cc7
15eca4a3f7350423cf4db0b4c30d1968
ea991bc9334b36a6b958f564ee716776
2a385fe7bed9899d77d05cb8e302d557
NJRAT copies and associated launchers
IP addresses35.157.111[.]131
3.68.56[.]232
3.67.15[.]169
Infrastructure contacted by NJRAT
Domain / Port7.tcp.eu.ngrok[.]io:12684ngrok endpoint contacted by NJRAT
File names / MD5%TEMP%\rockstargames.exe%TEMP%\P3usMXh1h4.batC:\Users\Default\Local Settings\[RANDOM FILE NAME].exe
8da3fe3664d81226b0fb2a50a0537d4f
DCRAT installer components and binary
Hosts-file entries0.0.0.0 app.adjust.com
0.0.0.0 app.adjust.io
0.0.0.0 app-sj01.marketo.com
0.0.0.0 t.appsflyer.com
0.0.0.0 analytics.ff.avast.com
0.0.0.0 analytics.ns1.ff.avast.com
0.0.0.0 v7event.stats.avcdn.net
0.0.0.0 v7.stats.avcdn.net
0.0.0.0 ads.avocet.io
0.0.0.0 telemetry.battle.net
0.0.0.0 analytics.rollout.io
0.0.0.0 metrics.ol.epicgames.com
0.0.0.0 a.fiksu.com
0.0.0.0 sdk.fiksu.com
0.0.0.0 settings.crashlytics.com
0.0.0.0 e.crashlytics.com
0.0.0.0 insights-collector.gog.com
0.0.0.0 ssl.google-analytics.com
0.0.0.0 ssl-google-analytics.l.google.com
0.0.0.0 static.hotjar.com
0.0.0.0 flow.lavasoft.com
0.0.0.0 telemetry.servers.getgo.com
0.0.0.0 telemetry.malwarebytes.com
0.0.0.0 ws.mcafee.com
0.0.0.0 analytics.ccs.mcafee.com
0.0.0.0 analyticsdcs.ccs.mcafee.com
0.0.0.0 gate.hockeyapp.net
0.0.0.0 api.mixpanel.com
0.0.0.0 decide.mixpanel.com
0.0.0.0 ads.mopub.com
0.0.0.0 incoming.telemetry.mozilla.org
0.0.0.0 h.online-metrix.net
0.0.0.0 analytics.paddle.com
0.0.0.0 treasuredata.com
0.0.0.0 in.treasuredata.com
0.0.0.0 redshell.io
0.0.0.0 api.redshell.io
0.0.0.0 carcharodon.trendmicro.com
0.0.0.0 cdn.segment.com
0.0.0.0 api.segment.io
0.0.0.0 mobile-service.segment.com
Entries added to the Windows hosts file by DCRAT
Domain / IP addressa0700877.xsph[.]ru
141.8.197[.]42
DCRAT command-and-control infrastructure
File name / MD5%TEMP%\adminapp.exe
dfdf5e5b78d2ec764c0e5641cf9a0d26
Mercurial Grabber infostealer binary
URLhttps://discord[.]com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y0M_A86oJHp00O-l8F4jakfVhqFXzMBoy1uBDdj2rBLcDiscord webhook used for stolen-data exfiltration
File names / MD5%TEMP%\gta6.exe%USERPROFILE%\AppData\Roaming\svchost.exe
b9648ec8cc806e7661aabcfc91dc836c
Chaos ransomware binaries
File nameread_it.txtNote dropped in folders affected by Chaos ransomware
File name / MD5%TEMP%\YandexPackLoader.exe
1ec9eff863dc4418d1498bc3d904899d
Browser installer included in the malicious ISO
File name / MD5%TEMP%\find.vbs
0e39e8d7b641bcda4376ebbfeff7b12e
Script that displays the fake “license not found” message
Email address[email protected]Address displayed by the fake installer for alleged crack updates

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/fake-gta-6-downloads/