Verticals Targeted: Gamers
Regions Targeted: Eastern Europe
Related Families: Chaos, Mercurial Grabber, DCRAT, NJRAT
Executive Summary
Threat actors are exploiting anticipation surrounding Grand Theft Auto VI by distributing fake leaked game ISOs containing multiple malware families. Huntress observed a malicious installer deploying NJRAT, DCRAT, Mercurial Grabber, and Chaos ransomware functioning effectively as a wiper, while disguising activity behind a staged license failure. The campaign continues a longstanding pattern of attackers abusing pirated games, cracks, cheats, and compromised mods as malware-delivery vectors.
Key Takeaways
- Threat actors are distributing fake leaked GTA6 ISOs through SEO poisoning, gaming forums, social media, and torrent sites. Some samples are padded with junk data to exceed 100 GB and appear consistent with a legitimate AAA game download.
- The malicious installer deploys multiple payloads, including NJRAT, DCRAT, Mercurial Grabber, and Chaos ransomware, providing attackers with remote-access, credential-theft, surveillance, and destructive capabilities. The Chaos ransomware payload effectively functions as a wiper, encrypting files 200 MB or smaller while overwriting larger files with random data and providing victims no mechanism to pay for or recover their files.
- Gaming-related malware distribution predates this campaign. Threat actors have repeatedly abused pirated games, cracks, cheats, and even compromised legitimate modding ecosystems to deliver downloaders, RATs, infostealers, cryptocurrency-focused malware, and other malicious payloads.
Background
Threat actors are exploiting interest in the upcoming release of Grand Theft Auto VI (GTA6) to distribute malware through fake leaked copies of the game. Huntress identified malicious GTA6 ISO files distributed through search engine optimization (SEO) poisoning, gaming forums, social media, and torrent sites. Some malicious ISOs exceed 100 GB but contain large quantities of junk data apparently intended to make the download size appear consistent with that of a modern AAA game.
The campaign represents the latest example of a long-established technique in which threat actors exploit demand for games and unofficial gaming content as a malware-delivery mechanism. Between July 2022 and July 2023, Kaspersky detected 4,076,530 attempts to download 30,684 unique files masquerading as popular games, mods, cheats, and other gaming-related software, affecting 192,456 users worldwide. Downloaders accounted for 89.7% of detected files, followed by adware and Trojans.
Information stealers have also been distributed using gaming-related lures. Malware such as RedLine Stealer and Lumma Stealer have been hidden in files masquerading as gaming software and cracked games, including distribution through compromised YouTube channels advertising cracks and mods.
Threat actors have additionally demonstrated that users do not necessarily have to intentionally pirate software to encounter gaming-related malware. In 2023, the Fractureiser campaign infected Minecraft mods and plugins distributed through CurseForge and BukkitDev. Later stages of the malware could steal browser credentials, Discord credentials, Microsoft and Minecraft credentials, manipulate cryptocurrency addresses, and propagate into additional Java archive files on infected systems. Compromised CurseForge credentials were also used to access established mod projects and distribute infected JAR files.
In December 2023, attackers also breached Downfall, the standalone Steam release of a fan-created Slay the Spire expansion. The compromise allowed a malicious version to replace the legitimate Steam download for approximately one hour on December 25. The incident was subsequently associated with distribution of the Epsilon information stealer.
These incidents illustrate that gaming-related malware distribution encompasses more than conventional software piracy. Cracks, cheats, fake unreleased games, malicious uploads, compromised mods, and compromised community projects can all provide threat actors with opportunities to exploit users' willingness to execute unfamiliar software.
Infection Chain
In the GTA6 campaign analyzed by Huntress, infection begins when a victim mounts the malicious ISO and launches gta6installer.exe. The executable displays a Russian-language installer claiming that the supposed leaked game is unlicensed. The installer warns the victim that installation may eventually produce a "License not found" error and provides an email address that purportedly allows the victim to request an updated crack.
This warning serves an additional social-engineering purpose. After the malware installation completes, WScript.exe executes find.vbs, which deliberately displays the predicted "license not found" message. The expected failure provides the victim with a plausible explanation for why the supposed game does not launch while malware has executed in the background.
During installation, numerous executables and scripts are written to %TEMP%, several using filenames intended to resemble legitimate GTA, Rockstar Games, Steam, or Windows components. A batch file named checkinternetconnection.bat launches Microsoft Edge and connects to clck[.]ru/34uJnp to verify internet connectivity before the infection proceeds with unpacking and installing its malware components.
NJRAT
The infection deploys several instances of NJRAT. NJRAT provides extensive remote-access functionality, including command-shell access, keylogging, connected-camera access, browser credential theft, file upload and download, registry and process modification, desktop monitoring, screenshots, and theft of cryptocurrency-related information. Observed NJRAT instances create Windows Firewall rules and communicate with several AWS-hosted IP addresses.
The malware also communicates through the ngrok tunneling endpoint 7.tcp.eu.ngrok[.]io:12684. Huntress identified three additional NJRAT copies, known as license.exe, rockstargamescrashfixer.exe, and rockstarservices.exe, although these samples did not exhibit additional observed network or child-process activity during analysis.
DCRAT
The ISO additionally deploys DCRAT through rockstargames.exe. The executable drops %TEMP%\P3usMXh1h4.bat, which configures the NTP server, installs a randomly named DCRAT executable under C:\Users\Default\Local Settings\, and deletes itself. In Huntress's observed environment, the installed executable was named UserOOBEBroker.exe.
DCRAT communicates with a0700877.xsph[.]ru, infrastructure Huntress notes has appeared on malicious blocklists for several years. The RAT provides capabilities including screenshot capture, mouse control, audio-device discovery, window tracking, clipboard access, and registry read/write functionality. The executable rockstargames.exe also modifies the Windows hosts file to sinkhole several telemetry and residential antivirus-reporting services.
Mercurial Grabber
The malicious ISO installs Mercurial Grabber as adminapp.exe. The infostealer is capable of collecting:
- Roblox Studio cookies
- Minecraft session data
- Discord tokens
- Google Chrome passwords and cookies
- System information, IP addresses, and geolocation data
- Windows product keys
- Screenshots
The malware exfiltrates collected information through a Discord webhook. The gaming-specific data targeted by Mercurial Grabber is noteworthy within the context of the campaign. In addition to conventional browser credentials and system information, the malware specifically targets Minecraft and Roblox-related information, reinforcing the utility of gaming-focused lures for accessing both conventional credentials and gaming accounts.
Chaos Ransomware Used as a Wiper
The most destructive component identified by Huntress is an instance of Chaos ransomware deployed through gta6.exe. Although Chaos is conventionally categorized as ransomware, the observed implementation effectively operates as a wiper rather than a financially motivated ransomware payload. The payload executes its destructive functionality only when the user has administrator privileges. The executable gta6.exe first creates %USERPROFILE%\AppData\Roaming\svchost.exe. The ransomware then disables recovery options, deletes drive shadow copies, and modifies boot configuration settings to disable recovery and ignore boot failures.
Files of 200 MB or smaller are encrypted using AES with a randomly generated 20-character password and assigned a random four-character extension. Files larger than 200 MB are instead overwritten with random data, effectively destroying their contents. The malware targets non-system drives before processing user directories, shared data, %APPDATA%, and OneDrive locations. The malware subsequently creates read_it.txt ransom notes stating that the victim's files have been encrypted permanently. No payment or recovery mechanism is provided. Huntress therefore assesses that the actors are using Chaos for destructive purposes rather than attempting conventional ransomware monetization.
Suspected Regional Targeting
Several characteristics suggest that the malicious ISO may have initially been intended for Russian or Eastern European users. The fake installer communicates with the victim in Russian, while the ISO additionally installs Yandex Browser, which Huntress notes is popular in Russia and Eastern Europe. These indicators should not be treated as definitive attribution or proof of exclusive geographic targeting. Huntress characterizes the regional connection as a possibility, and the campaign's distribution through search engines, social media, forums, and torrent sites could expose users outside the suspected target population.
Analyst Commentary
The GTA6 campaign demonstrates why gaming-related threats should not be dismissed as a problem confined to personal gaming systems. Attackers are exploiting an unusually effective combination of anticipation, piracy, social engineering, and user expectations. Someone intentionally executing a supposed crack may expect unusual warnings, antivirus detections, administrator prompts, or installation failures that would immediately appear suspicious in conventional software. In this campaign, the operators exploit those expectations directly by warning victims that the leaked game may generate a licensing error and then deliberately producing that error.
The number and variety of payloads also create a detection problem that extends beyond identifying a single malware family. One installation can expose an endpoint to multiple RATs, credential theft, browser and gaming-session theft, C2 infrastructure, and irreversible file destruction. Defenders therefore need visibility into the entire malicious package and its constituent artifacts, rather than relying on a single filename, hash, signature, or malware-family classification.
This is precisely where PolySwarm provides defenders with an advantage over single-engine analysis. PolySwarm's crowdsourced threat-detection marketplace allows suspicious files and URLs to be evaluated by a diverse ecosystem of commercial and specialized detection engines, giving security teams broader visibility into how different detection technologies assess the same artifact. Instead of betting endpoint security on one vendor's ability to recognize every component of a multi-payload package, defenders can use PolySwarm to rapidly compare detections, identify malicious artifacts, enrich investigations, and surface threat intelligence that may otherwise remain fragmented across individual tools.
IOCs
PolySwarm has multiple samples of malware associated with this activity.
f2a06bbfcfa3a06b9016c1f43c02b8d1f9216ef80fd29d99a519e03b4a444b92
e84826ff4599afa4767ebfa4eec90df0e1a0da991961d28bf23afe2ff19c1c5c
a8c60f952c9d7a73652877074ac4aba940e414c1518a4b1406d8ccf836d24964
43ed19c70200580f95cd31098df1217ce0305adc83e7950f00a48e9451f9192e
118ef74ca62cd5a122154bf3eb14e0d2b16a685a7c7aaede85e62b10096222cf
aa2075698965c994c60203ab8b2f99f77c01add721a60258f3d2fa20a4787ac7
dc74dd29df38d259a4bbd0c60c0717a74ee8c35f5b1339d52c67fff5f8a5348f
3ff31781fee2a0ae1e7187b4fe60b80f218d06d1434771c190f08442d3e60bc1
b82c7f077bcc4ee0714ebe35c5467790897b1f6f02283888ad5f0af07d4ba1ed
Don’t have a PolySwarm account? Go here to sign up for a free Community plan or subscribe.
Contact us at hivemind@polyswarm.io | Check out our blog | Subscribe to our reports.