Cybercriminals are taking advantage of the intense anticipation surrounding Grand Theft Auto VI by distributing fake game downloads that are laced with malware. These deceptive downloads target individuals searching for early versions or leaked copies of the game.
The fraudulent downloads are propagated through manipulated search results, gaming communities, torrent platforms, and social media channels. Despite some fake ISO files exceeding 100GB, this size is largely filled with unnecessary data to make the files seem legitimate.
Malicious Software Hidden in Fake Game Files
According to experts at Huntress, one detected package included a combination of remote-access malware, an information thief, file-deleting ransomware, and an additional web browser. This operation appears to be focused primarily on Russian-speaking users, indicated by Russian-language prompts and ransom notes.
Huntress revealed in a report shared with Cyber Security News that the absence of any genuine GTA 6 demo or leaked version is being exploited by this campaign. This situation mirrors previous incidents where fake GTA 6 demos were used to compromise devices.
Deceptive Installation Process
The malware infection starts when users mount the fake game image and initiate what seems to be an installer. The installer uses an outdated GTA 5-style icon and displays a misleading message in Russian about the game’s crack being invalid. This message is part of the ruse, as the installation completes with a “license not found” error, making users believe the game failed due to a missing license while malware runs covertly.
After installation, the malware deploys several files into the Windows temporary folder and checks internet connectivity. It then installs multiple instances of NJRAT, which can record keystrokes, capture screenshots, access webcams, and more. Additionally, DCRAT is deployed to monitor windows, capture clipboard data, and alter registry settings.
Ransomware Acts as a Data Wiper
The most harmful component is the Chaos ransomware, which, rather than demanding payment, acts as a data wiper. It encrypts small files while overwriting larger ones, rendering them irrecoverable. If the infected device has administrator privileges, the malware deletes shadow copies and disables recovery options, exacerbating the damage by targeting personal folders, shared data, saved games, and cloud-synced storage.
Users should steer clear of unofficial game releases and suspicious download pages. If a suspected fake GTA 6 installer is run, it’s crucial to disconnect from the network, reset passwords from a secure device, enable two-factor authentication, and reinstall the system. Keeping security software updated can help detect older malware families involved in this scheme.
This malicious campaign underscores the vulnerabilities associated with highly anticipated game releases, which can be exploited by attackers to execute social engineering scams. Gamers are advised to wait for official announcements and downloads from legitimate sources.
