There is no playable leaked copy of Grand Theft Auto VI. There are a great many enormous files claiming to be one, and Huntress has taken one of them apart. The disc image it examined does not only rob whoever mounts it. It destroys their files on the way out.
Fake GTA 6 images are being seeded through SEO-poisoned search results, gaming forums, torrent trackers and social media posts. Some run past 100GB, which is a convincing size for a modern game and is mostly junk padding; the malicious contents inside are a tiny fraction of that. This is the third distinct GTA 6 lure we have written up in three weeks, after fake demo sites pushing a password stealer and a fake leak site that drains whatever crypto wallet you connect. This is the destructive one.
An installer that warns you it might fail
Mount the image and you are presented with gta6installer.exe, which carries a GTA 5 icon. Run it and a Russian-language notice explains that the product is unlicensed because the game is unreleased, and that if you see a "License not found" error you should email the address provided so the crack can be updated. The installer then deliberately displays exactly that error. Huntress emailed the address and had received no reply by publication.
What actually happens is that a dozen files land in the user's %TEMP% folder, most named after Rockstar products. A batch script opens Microsoft Edge against a shortened link to confirm the machine is online, then the rest unpack.
Six remote access trojans, thrown at the wall
The bundle carries six copies of NJRAT, three of which actually ran during analysis. Each writes its own Windows Firewall rule and reaches out to three AWS-hosted addresses, 35[.]157[.]111[.]131, 3[.]68[.]56[.]232 and 3[.]67[.]15[.]169, plus a tunnel at 7[.]tcp[.]eu[.]ngrok[.]io on port 12684. Another file drops DCRAT under a folder in C:\Users\Default and calls home to a0700877[.]xsph[.]ru at 141[.]8[.]197[.]42, a domain that has sat on blocklists for years. That component also rewrites the Windows hosts file to sinkhole antivirus and telemetry reporting. An infostealer called Mercurial Grabber, taken straight off GitHub where it is advertised for educational purposes, collects Chrome passwords and cookies, Discord tokens, Minecraft and Roblox session data, Windows product keys and screenshots, and ships them out through a Discord webhook.
Much of this is old code. Huntress found components dating back to 2023, repurposed for an opportunistic campaign rather than written for it. The other three NJRAT copies never spawned a child process or made a connection at all.
Ransomware with nobody to pay
The last component is a build of the Chaos ransomware family, and it only runs if the user is an administrator. It deletes shadow copies, disables Windows recovery and tells the boot configuration to ignore failures, then sets the desktop wallpaper to a SpongeBob image with a Russian message claiming credit for the attack. Files of 200MB or less are encrypted with AES under a randomly generated 20-character password and given a random four-character extension. Files larger than 200MB are simply overwritten with random data.
The ransom note, dropped into every folder as read_it.txt, tells the victim the operator has no way to accept payment and the files are gone for good. Whether that is honesty or laziness, the outcome is identical. This is a wiper in a ransomware costume, and there is no key being held anywhere you could buy it back from.
There is nothing to download yet
The game is still around three months from release, and until then any ISO, demo or early build on offer is a lure. Because this payload targets user folders, mapped drives and OneDrive before anything else, the only reliable recovery is a backup taken before the install, held somewhere the machine cannot reach. Huntress credits Jon Semon, Andrew Brant and Lindsey O'Donnell-Welch for the investigation, and its full write-up lists the hashes.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.