ZeroHour
Story · 1 source · 1 articlefirst updated ()1

Fake GTA 6 'leaked build' ISOs deliver NJRAT, DCRAT, Mercurial Grabber, and Chaos ransomware wiper

mediumMalwareexploited in the wildimportance 47
What's new: First merged summary for this story (no prior dashboard entry). Chronology: Huntress's 2026-09-09 analysis established the fake GTA6 ISO, the fake license error, the NJRAT/DCRAT C2 infrastructure (AWS IPs, ngrok, xsph.ru domain), and an unnamed wiper component. Trade coverage on 2026-09-10 (Help Net Security, GBHackers, Cyber Security News) added the malware names (Chaos ransomware, Mercurial…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Huntress found fake Grand Theft Auto VI ISOs (no official GTA6 demo or playable leak exists) padded with junk data to roughly 100 GB and spread via SEO poisoning, torrents, forums, and social media. The installer shows a fake Russian 'License not found' error…

Huntress analyzed a malicious ISO masquerading as a leaked Grand Theft Auto VI build, noting there is no official GTA6 demo or leaked playable copy. The fake gta6installer.exe shows a Russian-language 'License not found' error (displayed via a Visual Basic script, per GBHackers) that directs users to an attacker-controlled Gmail address and conceals payloads already installed, then drops GTA6-branded files into %TEMP%. The bundle includes repurposed 2023-era NJRAT, DCRAT, the Mercurial Grabber infostealer, and a Chaos ransomware variant used destructively as a wiper; Help Net Security also reports a Yandex Browser drop. Three NJRAT copies create Windows Firewall rules and connect to AWS-hosted IPs 35.157.111.131, 3.68.56.232, and 3.67.15.169 plus an ngrok tunnel; DCRAT installs as UserOOBEBroker.exe in C:\Users\Default\Local Settings and communicates with a0700877.xsph.ru (141.8.197.42). Per GBHackers, Mercurial Grabber harvests browser passwords, cookies, Discord tokens, Roblox and Minecraft session data, Windows product keys, and cryptocurrency details, exfiltrating via a Discord webhook; Cyber Security News adds that the RATs provide keylogging, screenshots, webcam, and clipboard access. The Chaos wiper encrypts files up to 200 MB (with AES, per GBHackers; Cyber Security News describes overwriting files larger than 200 MB with random data) and destroys larger ones, deletes shadow copies (for admin users, per Cyber Security News), disables Windows recovery, and demands no ransom; GBHackers attributes it to the 'ASHA Hacker Team' and says it is launched through gta6.exe. ISO sizes are reported as 'up to 100 GB' (Huntress) with some images 'exceeding 100 GB' (GBHackers, Cyber Security News). Distribution uses SEO poisoning, gaming forums, torrent sites, and social media; Russian-language prompts suggest the operators target Russian-speaking gamers. Huntress characterizes the campaign as opportunistic and 'everything-at-once.' Most components date to 2023, and up-to-date Windows Defender detects them (Help Net Security); Cyber Security News also reports Hosts file changes that block telemetry and security-reporting services.

  • There is no official GTA6 demo or leaked playable copy; the ISO masquerades as a leaked build (Huntress).
  • ISOs are padded with junk data to around 100 GB (Huntress: 'up to 100 GB'; GBHackers and Cyber Security News: some images exceed 100 GB).
  • gta6installer.exe shows a Russian 'License not found' error (via a Visual Basic script per GBHackers) directing users to an attacker-controlled Gmail address, then drops GTA6-branded files into %TEMP%.
  • Three repurposed 2023-era NJRAT copies create Windows Firewall rules and contact AWS IPs 35.157.111.131, 3.68.56.232, and 3.67.15.169 plus an ngrok tunnel.
  • DCRAT installs as UserOOBEBroker.exe in C:\Users\Default\Local Settings and communicates with a0700877.xsph.ru (141.8.197.42).
  • Mercurial Grabber steals browser passwords, cookies, Discord tokens, Roblox and Minecraft session data, Windows product keys, and cryptocurrency details, exfiltrating via a Discord webhook (GBHackers).
  • NJRAT and DCRAT provide keylogging, screenshots, webcam, and clipboard access (Cyber Security News).
  • A Chaos ransomware variant acts as a wiper: encrypts files up to 200 MB (AES per GBHackers; Cyber Security News describes overwriting files over 200 MB with random data), deletes shadow copies, disables recovery, and demands no ransom.

Coverage timeline

  1. · 7d ago
    Huntress· 45
    Grand Theft Auto VI hype leads to malware

    Fake GTA6 ISO downloads spread via SEO poisoning, torrents, and forums deliver NJRAT, DCRAT, an infostealer, and wiper ransomware.