Executive Summary
Threat actors are currently exploiting the significant public anticipation for Grand Theft Auto VI by distributing malicious ISO files masquerading as leaked versions of the game. These files are spread via SEO poisoning, gaming forums, and torrent sites. While the installers present as legitimate AAA game files (sometimes exceeding 100GB in size due to junk data), they actually deploy a suite of older, repurposed malware families.
The attack chain involves a fake Russian-language installer that drops multiple Remote Access Trojans (NJRAT, DCRAT) and the Mercurial Grabber infostealer. The final stage involves Chaos ransomware, which in this campaign acts as a wiper by overwriting files larger than 200MB with random data rather than providing a recovery mechanism. The campaign appears specifically tailored to target Russian-speaking users, evidenced by the installer language, the use of Yandex browser, and localized ransom notes.
This activity highlights the effectiveness of using high-profile media releases as social engineering lures. Organizations and individuals are advised that no legitimate GTA6 demo or leak currently exists; any such downloads should be treated as high-risk malicious content.
