Fake GTA 6 'leaked build' downloads deliver RATs, infostealer, and Chaos wiper to impatient gamers
Huntress found malware-packed ISOs posing as leaked GTA 6 builds, spread via SEO poisoning and torrents, that install NJRAT, DCRAT, Mercurial Grabber, and a Chaos ransomware variant used destructively as a wiper.
Huntress analyzed malicious ISO images disguised as leaked Grand Theft Auto VI builds, distributed through SEO-poisoned search results, torrent sites, gaming forums, and social media; some fake ISOs exceed 100 GB, padded with junk data. Running the installer (gta6installer.exe) shows a fake 'License not found' error — displayed via a Visual Basic script per GBHackers — while game-named executables are staged in %TEMP% and payloads install silently: NJRAT and DCRAT remote access trojans (offering keylogging, screenshots, webcam, and clipboard access), the Mercurial Grabber infostealer, a Chaos ransomware variant used as a wiper, and a Yandex Browser drop. Mercurial Grabber harvests browser passwords, cookies, Discord tokens, Roblox and Minecraft session data, Windows product keys, and cryptocurrency details, exfiltrating via a Discord webhook. The Chaos variant encrypts files up to 200 MB with AES, overwrites larger files with random data, deletes shadow copies (for admin users, per Cyber Security News), and disables Windows recovery, with no ransom demanded; GBHackers attributes it to the 'ASHA Hacker Team', a claim not repeated in the other reports. Most components date to 2023 and are detected by up-to-date Windows Defender.
- Huntress analyzed a fake GTA 6 ISO whose gta6installer.exe shows a fake 'License not found' error (via a Visual Basic script, per GBHackers) while payloads install silently.
- The bundle contains NJRAT and DCRAT remote access trojans, the Mercurial Grabber infostealer, and a Chaos ransomware variant acting as a wiper, plus a Yandex Browser drop.
- NJRAT and DCRAT provide keylogging, screenshots, webcam, and clipboard access (Cyber Security News).
- Mercurial Grabber steals browser passwords, cookies, Discord tokens, Roblox and Minecraft session data, Windows product keys, and cryptocurrency details, exfiltrated via a Discord webhook.
- Chaos encrypts files up to 200 MB with AES, overwrites larger files with random data, deletes shadow copies, and disables Windows recovery; no ransom is demanded.
- GBHackers attributes the wiper to the 'ASHA Hacker Team'; the other reports do not name an actor.
- Distribution runs through SEO-poisoned search results, torrent sites, gaming forums, and social media; some fake ISOs exceed 100 GB padded with junk data.
- The installer stages game-named executables in %TEMP%; malware adds firewall rules, modifies the hosts file to block telemetry and security-reporting services, and uses AWS and ngrok infrastructure.
Coverage timelineoldest first · each row is one article
- · 6d agoFake GTA 6 download delivers malware-packed bundle to impatient gamers
Help Net Security· 45
Huntress found malware disguised as a leaked GTA 6 download bundling NJRAT, DCRAT, an infostealer, and Chaos ransomware used as a wiper.
- · 6d agoFake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
GBHackers· 47
Huntress found fake GTA 6 installer ISOs spreading NJRAT, DCRAT, Mercurial Grabber and a Chaos ransomware wiper that steals credentials.
- · 6d agoHackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cyber Security News· 45
Huntress tracked fake GTA 6 downloads distributing NJRAT, DCRAT, Mercurial Grabber, and Chaos ransomware used as a wiper against gamers.