GTA 6 Download Scam: Malware-Packed Bundle Targets Impatient Gamers
Researchers warn of malicious software disguised as an unauthorized version of Grand Theft Auto VI, targeting eager fans.
The Threat of Fake GTA 6 Malware
Fake GTA 6 Grand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. A cybersecurity firm identified malicious software masquerading as an unauthorized version of the game, targeting fans eager to access it prematurely.
The Deceptive Installer
The sample analyzed contained multiple malware components designed to exploit user curiosity. Researchers described an opportunistic package combining a deceptive installer, remote access tools, data stealers, and destructive ransomware. The malicious ISO file includes a fake installer that mimics the official GTA 5 icon.
When executed, the file gta6installer.exe displays a Russian-language warning about a missing license key and provides a contact address for resolution. This message is part of a staged process to mislead users. After installation, a script triggers the error, creating a false impression that the game failed to launch while secretly deploying malware in the background.
Malware Components and Tactics
The contact address listed in the installer remained unresponsive during investigation. The malware components within the ISO date back to 2023, repurposed for this attack. Files placed in the system’s %TEMP% directory are branded with GTA 6 identifiers to evade suspicion.
A batch file named checkinternetconnection.bat initiates Microsoft Edge and connects to a domain linked to the malicious payload. This step confirms internet access before proceeding to install additional threats.
Remote Access Tools and Data Theft
The package includes multiple remote access tools (RATs) such as NJRAT and DCRAT. NJRAT provides attackers with shell access, keystroke logging, camera control, and browser credential theft. DCRAT enables mouse control, screenshot capture, clipboard access, and registry modifications. It also alters the Windows hosts file to block communication with security vendors.
An open-source infostealer called Mercurial Grabber is included, designed to collect Discord tokens, browser credentials, gaming session data, and system keys. It transmits stolen information via a Discord webhook.
Ransomware and System Destruction
The ransomware component, a variant of Chaos, functions as a wiper rather than a traditional encryptor. It targets files under 200MB for encryption and overwrites larger files with random data, rendering them irrecoverable. System backups are deleted, and recovery options are disabled.
The desktop wallpaper is replaced with a SpongeBob image and a ransom note claiming responsibility from the “ASHA Hacker Team.” The message states, “Your files has been encrypted by achvz1om. You don’t have paypal or other banks so you don’t can donate me. Your files has been encrypted forever.”
Targeting Specific Audiences
The presence of Russian-language elements and the targeting of specific user groups suggest the attack is directed at Russian-speaking audiences. Despite the complexity of the payload, researchers noted that the malware relies on outdated techniques. Modern versions of Windows Defender are capable of detecting and blocking the threats without requiring additional mitigation.
Expert Advice and Cybersecurity Measures
Cybersecurity experts advise against downloading unverified game copies, emphasizing that such actions increase the risk of compromise. The attack highlights the ongoing trend of threat actors exploiting popular media releases to distribute malicious software. Users are encouraged to verify sources and maintain updated security solutions to prevent similar incidents.
“Your files has been encrypted by achvz1om. You don’t have paypal or other banks so you don’t can donate me. Your files has been encrypted forever.”
