GTA 6

Fake GTA 6 installers carry file-destroying malware with no ransom demand, researchers say

fake gta 6 installer

A fake Grand Theft Auto VI installer analysed by security firm Huntress bundles two remote access trojans, an infostealer and ransomware configured to destroy files rather than hold them for payment. The note it leaves behind tells victims there is no way to pay.

Ransomware normally has a business model. Files are held hostage, a price is named, and somewhere in the transaction there is a wallet address or a support portal. It is extortion, and extortion requires a way to collect.

The malware that security firm Huntress described in analysis published on September 9, 2026, hidden inside a fake Grand Theft Auto VI download, appears to skip that step. It encrypts files below a certain size, overwrites larger ones, deletes Windows shadow copies, disables recovery options, and leaves a text file in each affected folder. The note reads, in part:

hello, your files has been encrypted by achvz1om i don’t have paypal or other banks so you don’t can donate me :XD

No price is named and no wallet is given. Huntress concluded that the actors did not appear to be seeking a ransom, and that a well-known ransomware family called Chaos had effectively been repurposed as a wiper.

A download that cannot be what it claims

The delivery is unglamorous. According to Huntress, threat actors have seeded search results, gaming forums, torrent sites and social media with disc image files claiming to be early or leaked copies of GTA 6. Some of the ISOs in circulation cross 100GB — not because the payload is large, but because a real AAA game would be roughly that size. Huntress found the bulk of such files to be junk data, padding to make the lie plausible at a glance.

It is worth noting how difficult the offer is to credit. Rockstar has not announced a publicly available PC version of GTA 6, and Huntress said it saw no sign of an actual leaked, playable copy of the game being distributed online.

Mount the analysed image and you get gta6installer.exe, which — in a detail that ought to be a giveaway — carries the icon for GTA 5. Run it and a message appears in Russian. Huntress provided an approximate translation using online tools:

Welcome to the GTA 6 installer. This product is not licensed because it is a leaked, unreleased game… If you receive the error “License not found,” it means that the crack has been fixed. Write to [email address] about it, and we will update the crack so that it works perfectly. Enjoy the game!

This is the most interesting part of the operation, and it is social engineering rather than code. The installer pre-announces the failure it is about to stage. When the installation finishes, a script called find.vbs displays an error reading “license not found” — exactly the message the victim was warned about. The game never runs, and the victim is given a ready explanation that has nothing to do with malware. Huntress emailed the address provided and said it had received no response as of publication.

Four kinds of malware at once

Behind the fake error, twelve files unpack into the system’s temporary folder, most named to blend in: rockstar.exe, steam.exe, gta6.exe, rockstargamescrashfixer.exe. A batch file opens Microsoft Edge, connects to a shortened URL to confirm the machine is online, and the installation proceeds.

What arrives is not one piece of malware but several kinds at once. Multiple copies of NJRAT, a long-established remote access trojan, which Huntress describes as able to open a shell, log keystrokes, reach connected cameras, take screenshots, steal browser credentials and collect cryptocurrency details. A copy of DCRAT, adding mouse control, clipboard access and registry read-write — and which rewrites the Windows hosts file to sinkhole telemetry endpoints belonging to Avast, McAfee, Malwarebytes, Trend Micro and others.

Then Mercurial Grabber, an infostealer freely available on GitHub under the customary description of being “for educational purposes only.” Huntress lists its targets as Discord tokens, Chrome passwords and cookies, Windows product keys, system and geolocation data, screenshots, Roblox Studio cookies and Minecraft session data. It sends what it collects out through a Discord webhook.

And finally a copy of the Yandex browser, which Huntress noted it could not explain. Given the installer’s Russian text, Huntress suggested the package may have been built with Russian-speaking users in mind.

What the wiper does

The Chaos component runs only if the user has administrator rights. When it does run, Huntress found that it disables recovery options, deletes shadow copies, and modifies the boot configuration to ignore failures. It changes the desktop wallpaper to an image of SpongeBob bearing the message “YOU HAVE BEEN HACKED BY THE ASHA HACKER TEAM!” — a different name to the one signed on the ransom note.

It then works through the drives. Files of 200MB and under are encrypted with AES using a randomly generated twenty-character password and given a random four-character extension. Files larger than 200MB are overwritten with random data. Non-system drives are processed first, followed by the desktop, documents, downloads, pictures, music, videos, favourites, saved games, and OneDrive if present.

Old tools, new packaging

The malware in this ISO is not new. Huntress found many of the files dating back to 2023. Mercurial Grabber is free to download. Three additional copies of NJRAT showed no further activity during Huntress’s analysis — the firm characterised the approach as a threat actor throwing an armful of RATs at the wall to see what would stick.

Huntress says that in each case, a currently updated version of Windows Defender can detect the malware and stop it from compromising the system. What distinguishes the campaign is not technical sophistication but the strength of the lure.

Months of the same trick

Huntress’s September analysis follows earlier reports of fake GTA 6 offers, and what the attackers appear to want has varied.

  • JuneNordVPN documents fake GTA 6 beta key sites, trojanised repacks targeting Windows users, and Android adware posing as a “GTA 6 Beta.”
  • 23 June — Malwarebytes reports sites selling “VIP early access” for hundreds of dollars in cryptocurrency.
  • 18 August — New GTA 6 gameplay footage and an apparent complete map of Leonida began circulating. A person or group calling itself Cyberleek claimed responsibility. Take-Two responded with takedowns and DMCA subpoenas seeking records from Microsoft and Discord.
  • 19 August — The Vidar sample examined by Malwarebytes was first spotted, one day after the Cyberleek material began circulating. Malwarebytes found it distributed through sites impersonating Rockstar and copying its genuine promotion for the Extended Look. The file was 1.1MB — far too small to contain a modern game.
  • 27 August — Rockstar’s Extended Look premiered on Netflix at 3pm ET, then on YouTube.
  • 9 SeptemberHuntress published its analysis of the RAT, infostealer and wiper bundle.

Huntress found different functionality in this sample; the report does not establish whether the operators are connected.

There is a further wrinkle. The genuine leaks were not disinterested either: according to Malwarebytes, leaked clips carried promotional material for a cryptocurrency token associated with Cyberleek, whose website solicited crypto donations and sold advertising placements in future GTA 6 videos. Recycled and AI-generated footage circulated alongside the real material. For anyone searching, real leaks, monetised leaks, fakes and malware could look much the same.

Rockstar’s difficult year

There is an uncomfortable symmetry in a Rockstar game being used as bait, because the company has been the subject of three separate security and leak stories in 2026.

In April, the extortion group ShinyHunters said it had compromised Anodot, a SaaS analytics provider with authenticated access to customer data warehouses, and used stolen tokens to reach Rockstar’s Snowflake environment. The group claimed to have taken 78.6 million business and analytics records. Rockstar said a limited amount of non-material company information had been accessed in connection with a third-party breach, and Snowflake stated that its own systems were not breached.

In August came the Cyberleek footage leaks. The August footage leaks followed the 2022 theft of development footage confirmed by Rockstar. And in September, the company’s unreleased game was documented as a malware lure.

The cited reports do not establish a connection between these incidents.

The legal picture

Conduct of this kind may violate computer-crime and fraud statutes, depending on the evidence and the jurisdiction — laws covering unauthorised damage to computer systems, fraudulent inducement, and the misuse of stolen credentials are all potentially engaged.

There is a recent case involving similar allegations. In July, federal authorities arrested a 21-year-old Florida man accused of distributing several malware-embedded games through Steam. Investigators say the scheme infected roughly 8,000 devices and drained approximately 80 cryptocurrency wallets of at least $220,000 over about two years, and that he was identified partly through Google cookie records and partly through gift card purchases made with the proceeds. The allegations have not been proven.

Scheduled for 19 November

Grand Theft Auto VI is scheduled to launch on 19 November 2026 for PlayStation 5 and Xbox Series X|S, following two delays. Huntress said it had seen no sign of a genuine leaked, playable copy in circulation, and Rockstar has not announced a demo or a publicly available PC version. Offers of one should be treated with suspicion.

If you ran an installer of this kind

  • Disconnect the machine from the network.
  • Reset passwords from a different device — credentials stored in browsers should be assumed compromised.
  • Sign out of active sessions everywhere. Changing a password does not necessarily invalidate an existing session, and Malwarebytes notes that a stolen session token may allow access without another two-factor prompt, depending on the service’s security controls.
  • Check gaming accounts specifically. Steam, Epic and similar accounts can hold saved payment methods and valuable inventories.
  • Huntress recommends a complete reimage of the affected system rather than a clean-up, along with enabling two-factor authentication wherever available.
  • Do not email the address in the installer.

Join the conversation

Your email address will not be published. Required fields are marked *