Fake GTA 6 Installer Steals Browser Passwords and Crypto Data From Gamers
Cybercriminals are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent 'leaked' game downloads that install malware. The malware bundle steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. The fake GTA 6 installer uses a layered approach to deploy multiple payloads, including the NJRAT remote-access trojan, which has extensive surveillance and theft capabilities.
The campaign demonstrates how cybercriminals are turning one of gaming's most anticipated releases into a high-volume initial-access lure. The malware can open a remote shell, log keystrokes, capture screenshots, access connected cameras, steal browser passwords, manipulate files and Registry entries, and collect cryptocurrency details.
Huntress researchers found that the associated loader modified the Windows hosts file to interfere with telemetry and residential antivirus reporting services. The ISO also drops adminapp.exe, identified as the Mercurial Grabber infostealer, which harvests Google Chrome passwords and cookies, Discord tokens, Roblox Studio cookies, Minecraft session data, Windows product keys, screenshots, system metadata, IP addresses, and geolocation information.
The targeting of Discord and game-session artifacts makes the campaign particularly risky for gamers. The most destructive payload is a Chaos ransomware variant launched through gta6.exe, which appears designed to disrupt victims permanently by deleting shadow-copy backups and overwriting larger files with random data.