Grand Theft Auto VI hype leads to malware
Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.
AI Analysis
Technical Summary
This campaign leverages the hype around Grand Theft Auto VI by distributing malicious ISO files that masquerade as leaked game versions. The analyzed malware package includes multiple components: RAT variants NJRAT and DCRAT, Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. Upon execution, the fake installer displays Russian-language messages and deploys malware into the %TEMP% directory. The malware enables credential theft, system control, data exfiltration, and destructive file encryption. The use of Russian language throughout the infection chain suggests targeting of Russian-speaking gamers. The malware components are repurposed tools from 2023, indicating an opportunistic attack exploiting gaming community interest. Distribution methods include SEO poisoning, gaming forums, social media, and torrenting sites. No known exploits in the wild or vendor patches are applicable as this is a malware campaign rather than a software vulnerability.
Potential Impact
The malware enables attackers to steal credentials, exfiltrate data, gain remote control over infected systems, and perform destructive file encryption that acts as a wiper. This can lead to significant data loss, privacy breaches, and system compromise for victims. The campaign specifically targets gamers seeking unauthorized copies of Grand Theft Auto VI, potentially resulting in widespread infection within this community. The inclusion of multiple malware families increases the attack's versatility and impact.
Mitigation Recommendations
No official patch or fix applies as this is a malware campaign rather than a software vulnerability. Defenders should avoid downloading or executing unauthorized or suspicious game files, especially those claiming to be leaked versions of unreleased games. Users should obtain games only from legitimate sources. Employ endpoint protection capable of detecting RATs, infostealers, and ransomware. Monitor for indicators of compromise such as the provided file hashes and domains. Educate users about risks of SEO poisoning and social engineering in gaming communities. There is no vendor-managed remediation for this threat.
Indicators of Compromise
- hash: ea991bc9334b36a6b958f564ee716776
- hash: 0e39e8d7b641bcda4376ebbfeff7b12e
- hash: 15eca4a3f7350423cf4db0b4c30d1968
- hash: 1ec9eff863dc4418d1498bc3d904899d
- hash: 2a0834560ed3770fc33d7a42f8229722
- hash: 2a385fe7bed9899d77d05cb8e302d557
- hash: 57b9c56ef97a7ada98257b23577bf5e3
- hash: 60a0f58001ea7be538cd42b651924cc7
- hash: 6b49f24d5d5b49127476bc385565f8b0
- hash: 8da3fe3664d81226b0fb2a50a0537d4f
- hash: a15e280a3fd65dfaa243bbe2dbf45e97
- hash: b9648ec8cc806e7661aabcfc91dc836c
- hash: dfdf5e5b78d2ec764c0e5641cf9a0d26
- domain: a0700877.xsph.ru
Grand Theft Auto VI hype leads to malware
Description
Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This campaign leverages the hype around Grand Theft Auto VI by distributing malicious ISO files that masquerade as leaked game versions. The analyzed malware package includes multiple components: RAT variants NJRAT and DCRAT, Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. Upon execution, the fake installer displays Russian-language messages and deploys malware into the %TEMP% directory. The malware enables credential theft, system control, data exfiltration, and destructive file encryption. The use of Russian language throughout the infection chain suggests targeting of Russian-speaking gamers. The malware components are repurposed tools from 2023, indicating an opportunistic attack exploiting gaming community interest. Distribution methods include SEO poisoning, gaming forums, social media, and torrenting sites. No known exploits in the wild or vendor patches are applicable as this is a malware campaign rather than a software vulnerability.
Potential Impact
The malware enables attackers to steal credentials, exfiltrate data, gain remote control over infected systems, and perform destructive file encryption that acts as a wiper. This can lead to significant data loss, privacy breaches, and system compromise for victims. The campaign specifically targets gamers seeking unauthorized copies of Grand Theft Auto VI, potentially resulting in widespread infection within this community. The inclusion of multiple malware families increases the attack's versatility and impact.
Defensive Guidance
No official patch or fix applies as this is a malware campaign rather than a software vulnerability. Defenders should avoid downloading or executing unauthorized or suspicious game files, especially those claiming to be leaked versions of unreleased games. Users should obtain games only from legitimate sources. Employ endpoint protection capable of detecting RATs, infostealers, and ransomware. Monitor for indicators of compromise such as the provided file hashes and domains. Educate users about risks of SEO poisoning and social engineering in gaming communities. There is no vendor-managed remediation for this threat.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.huntress.com/blog/fake-gta6-download-malware-analysis"]
- Adversary
- null
- Pulse Id
- 6aa18179c7eb1a5f0426ed7a
- Threat Score
- null
Indicators of Compromise
Hash
| Value | Description | Copy |
|---|---|---|
hashea991bc9334b36a6b958f564ee716776 | — | |
hash0e39e8d7b641bcda4376ebbfeff7b12e | — | |
hash15eca4a3f7350423cf4db0b4c30d1968 | — | |
hash1ec9eff863dc4418d1498bc3d904899d | — | |
hash2a0834560ed3770fc33d7a42f8229722 | — | |
hash2a385fe7bed9899d77d05cb8e302d557 | — | |
hash57b9c56ef97a7ada98257b23577bf5e3 | — | |
hash60a0f58001ea7be538cd42b651924cc7 | — | |
hash6b49f24d5d5b49127476bc385565f8b0 | — | |
hash8da3fe3664d81226b0fb2a50a0537d4f | — | |
hasha15e280a3fd65dfaa243bbe2dbf45e97 | — | |
hashb9648ec8cc806e7661aabcfc91dc836c | — | |
hashdfdf5e5b78d2ec764c0e5641cf9a0d26 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domaina0700877.xsph.ru | — |
Threat ID: 6aa24217acd9273b499d72b9
Added to database: 09/10/2026, 05:37:27 UTC
Last enriched: 09/10/2026, 05:53:34 UTC
Last updated: 09/10/2026, 16:40:50 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.