Skip to content
Breaking:

Cybersecurity Researchers Warn of Fake GTA 6 Installers Spreading Ransomware and RATs

Security firm Huntress identified malicious ISO files disguising remote access trojans and infostealers as leaked builds of Rockstar Games' upcoming title.

By The Company Wire4 min read
Share
Rockstar Games — Cybersecurity Researchers Warn of Fake GTA 6 Installers Spreading Ransomware and RATs
Rockstar Games — Cybersecurity Researchers Warn of Fake GTA 6 Installers Spreading Ransomware and RATs. Photo: TechRadar Pro.

Cybercriminals are capitalizing on public anticipation surrounding Rockstar Games' upcoming video game Grand Theft Auto 6 by distributing malicious software disguised as leaked early builds of the title, according to cybersecurity researchers at Huntress. First reported by TechRadar Pro, the fraudulent installers are being spread through torrent sites, gaming forums, social media channels, and websites optimized to appear high in search engine results via search engine optimization (SEO) poisoning.

Grand Theft Auto 6 is scheduled for official release on November 19, 2026. Developer Rockstar Games initiated preliminary work on the project more than a decade ago and has allegedly invested over $1 billion into its production, which would make it the most expensive video game development effort to date. Its predecessor, Grand Theft Auto 5, has sold more than 230 million copies worldwide since its release, generating high global demand for details on the upcoming sequel.

Threat activity surged in late August 2026 after an online individual using the pseudonym LEEK claimed to possess a working, playable build of the game roughly six months prior to its launch. The individual shared multiple screenshots and videos showing gameplay, including footage of a character using a rifle to spell out the alias on an in-game wall. Security analysts noted that while illicit downloads targeting unreleased titles are common, the widely shared leak claims significantly increased web searches for unauthorized installers.

Investigation by Huntress revealed that malicious actors are distributing disk image files, known as ISOs, designed to mirror legitimate software installation media. Several analyzed ISO packages were artificially inflated to file sizes exceeding 100 gigabytes to appear convincing, even though the actual malicious payloads occupied a much smaller fraction of that space. Researchers discovered that the packages contained multiple malware strains operating alongside a standard, non-malicious web browser.

The malicious components inside the packages included NJRAT and CDRAT, two strains of remote access trojans that allow external actors to gain unauthorized control of compromised devices. The installer also bundled Chaos Ransomware, a payload capable of encrypting system files, alongside an infostealer called Mercurial Grabber. Mercurial Grabber is designed to harvest stored Chrome passwords and cookies, Discord tokens, Minecraft session data, Roblox Studio credentials, system configuration details, IP addresses, geolocation markers, Windows product keys, and active desktop screen captures.

To prevent victims from immediately identifying the cyberattack when the game fails to load, the installer uses a deceptive social engineering message. During the installation process, a pop-up written in Russian alerts the user that the software is unlicensed and may not execute properly, advising them to contact a designated Gmail address to obtain an updated software crack. Once installation finishes, the application displays a secondary notice stating "License not found," masking the background malware execution as a routine software error.

While Huntress stated that the total number of infected systems cannot be precisely quantified, researchers emphasized that attempting to download cracked or pirated software poses inherent security threats, particularly when applied to unreleased commercial media. The firm noted that impatient consumers seeking early access create optimal conditions for threat actors to deploy scam campaigns.

Researchers highlighted that the malware strains packaged within the fraudulent ISO files are not new zero-day exploits, with several variants dating back multiple years. As a result, mainstream security software and built-in endpoint protection systems, such as Microsoft Windows Defender, are capable of identifying and blocking the threats before they compromise host machines.

For systems that executed the malicious installers, security professionals recommend immediately disconnecting the compromised hardware from all local networks and the internet. Affected users are advised to perform a complete system reimage, reset all account passwords from a separate secure device, and implement multi-factor authentication across all active services.

Sources

  1. TechRadar Pro

Company: Rockstar Games

Written by

The Company Wire

Newsroom · San Francisco

Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.