Skip to main content
Reconnecting to live updates…

Grand Theft Auto VI hype leads to malware

0
Medium
Published: 09/09/2026 (09/09/2026, 15:55:37 UTC)
Source: AlienVault OTX General

Description

Threat actors are exploiting anticipation for Grand Theft Auto VI by distributing malicious ISO files disguised as leaked game versions. These fake installers are spread through SEO poisoning, gaming forums, social media, and torrenting sites. The analyzed ISO contains multiple malicious components including several RAT variants (NJRAT and DCRAT), Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. When executed, the fake installer displays Russian-language messages and deploys malware to %TEMP% folders. The package includes data exfiltration capabilities, credential theft, system control features, and destructive file encryption. Based on Russian language usage throughout the infection chain, the campaign appears to target Russian-speaking gamers. The malware components date back to 2023, suggesting repurposed tools for this opportunistic attack.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 05:53:34 UTC

Technical Analysis

This campaign leverages the hype around Grand Theft Auto VI by distributing malicious ISO files that masquerade as leaked game versions. The analyzed malware package includes multiple components: RAT variants NJRAT and DCRAT, Mercurial Grabber infostealer, Chaos ransomware functioning as a wiper, and Yandex Browser. Upon execution, the fake installer displays Russian-language messages and deploys malware into the %TEMP% directory. The malware enables credential theft, system control, data exfiltration, and destructive file encryption. The use of Russian language throughout the infection chain suggests targeting of Russian-speaking gamers. The malware components are repurposed tools from 2023, indicating an opportunistic attack exploiting gaming community interest. Distribution methods include SEO poisoning, gaming forums, social media, and torrenting sites. No known exploits in the wild or vendor patches are applicable as this is a malware campaign rather than a software vulnerability.

Potential Impact

The malware enables attackers to steal credentials, exfiltrate data, gain remote control over infected systems, and perform destructive file encryption that acts as a wiper. This can lead to significant data loss, privacy breaches, and system compromise for victims. The campaign specifically targets gamers seeking unauthorized copies of Grand Theft Auto VI, potentially resulting in widespread infection within this community. The inclusion of multiple malware families increases the attack's versatility and impact.

Defensive Guidance

No official patch or fix applies as this is a malware campaign rather than a software vulnerability. Defenders should avoid downloading or executing unauthorized or suspicious game files, especially those claiming to be leaked versions of unreleased games. Users should obtain games only from legitimate sources. Employ endpoint protection capable of detecting RATs, infostealers, and ransomware. Monitor for indicators of compromise such as the provided file hashes and domains. Educate users about risks of SEO poisoning and social engineering in gaming communities. There is no vendor-managed remediation for this threat.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.huntress.com/blog/fake-gta6-download-malware-analysis"]
Adversary
null
Pulse Id
6aa18179c7eb1a5f0426ed7a
Threat Score
null

Indicators of Compromise

Hash

ValueDescriptionCopy
hashea991bc9334b36a6b958f564ee716776
hash0e39e8d7b641bcda4376ebbfeff7b12e
hash15eca4a3f7350423cf4db0b4c30d1968
hash1ec9eff863dc4418d1498bc3d904899d
hash2a0834560ed3770fc33d7a42f8229722
hash2a385fe7bed9899d77d05cb8e302d557
hash57b9c56ef97a7ada98257b23577bf5e3
hash60a0f58001ea7be538cd42b651924cc7
hash6b49f24d5d5b49127476bc385565f8b0
hash8da3fe3664d81226b0fb2a50a0537d4f
hasha15e280a3fd65dfaa243bbe2dbf45e97
hashb9648ec8cc806e7661aabcfc91dc836c
hashdfdf5e5b78d2ec764c0e5641cf9a0d26

Domain

ValueDescriptionCopy
domaina0700877.xsph.ru

Threat ID: 6aa24217acd9273b499d72b9

Added to database: 09/10/2026, 05:37:27 UTC

Last enriched: 09/10/2026, 05:53:34 UTC

Last updated: 09/10/2026, 16:40:50 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses