Fake GTA 6 “Build” Used to Trick Users Into Malware

About DFIR · Medium sophistication
Last updated August 25, 2026

A scam is using hype around Grand Theft Auto 6 to trick people into downloading a “leaked, playable build” from torrent sites. The file is mostly junk data, but it contains a small malware payload that tries to weaken Windows Defender and stop security tools, giving attackers control of the infected machine. Other nuggets in the roundup cover exposed AWS keys and multiple non-social-engineering threats (backdoor malware, a Zimbra RCE, and a power disruption).

Key findings

  • Scammers are posting a fake, “playable” GTA 6 pre-release build on torrent sites to lure downloads.
  • The advertised file is very large (113GB) and is largely padding/junk data wrapped around a small malicious payload.
  • The payload attempts to reduce defenses by whitelisting the system drive in Windows Defender and terminating security software.
  • The lure is made more believable by real interest generated from an unrelated leaker sharing authentic gameplay footage.

Who’s being targeted

  • Commonly targeted roles: All employees, IT/Security, Helpdesk.
  • Affected industries: Consumers / end users, Gaming community, Organizations where employees download pirated software.
  • Attack channels: website.
  • Impersonated: A torrent uploader claiming to share a leaked game build.

Awareness takeaways

  • Treat “leaked builds,” pirated software, and unofficial downloads as high-risk and avoid running them on any work device.
  • If a program tries to weaken security controls (e.g., Defender exclusions) or disables security tools, stop and report it immediately.
  • Be extra skeptical when a scam aligns with real news/hype, attackers often piggyback on genuine events to look credible.

Red flags to watch for

  • Too-good-to-be-true early access to a high-profile unreleased game
  • Unusually large download size used to look legitimate (padding/junk data)
  • Software asks for elevated permissions / attempts to change security settings
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

See a torrent called “GTA 6 Pre-Release Build (Playable), 113GB, leaked build”? That’s not early access, that’s a trap. That 113GB file? Almost all junk padding wrapped around a tiny malware payload that tries to whitelist your entire system drive in Windows Defender and kill your security tools. Scammers are riding real GTA 6 hype and leaked gameplay footage to make this look legit. The giveaway: a too-good-to-be-true leaked build that needs admin rights and immediately messes with Defender settings. If you ever see a “leaked” game or pirated software on a work device, especially one that touches Defender settings, don’t run it. Close it and report it to IT immediately.

Similar attacks

Phishing Email Pushes Fake Notepad++ Plugin

Phishing Email Pushes Fake Notepad++ Plugin

CERT-UA reported a real phishing campaign where victims receive an email with an image attachment that leads (via a shortened link) to a ZIP download. The ZIP contains a script disguised as a PDF, which installs a malicious Notepad++ plugin and sets up an automated task that repeatedly runs malware…

July 24, 2026
Typosquat RubyGems Stealer Hits Dev Machines

Typosquat RubyGems Stealer Hits Dev Machines

Researchers found 16 look‑alike (typosquatted) RubyGems packages that trick developers into installing a Windows information stealer. The malicious gems run code automatically during installation, pull down additional malware, and then steal browser logins and crypto wallet data before uploading it…

August 18, 2026
Fake Zoom Updates Install ScreenConnect Backdoor

Fake Zoom Updates Install ScreenConnect Backdoor

Researchers describe an active campaign ("SMOKE#SCREEN") where attackers trick users with realistic software update and document-themed lures to install a legitimate remote-control tool (ScreenConnect). Once installed, the attacker gains persistent remote access that can look like normal IT…

August 5, 2026
Steam Forum “Fix” Posts Push Malicious PowerShell

Steam Forum “Fix” Posts Push Malicious PowerShell

Attackers used fake Steam forum replies that looked like helpful troubleshooting steps for real gaming/PC problems. The posts tricked users into running PowerShell as an administrator, which then downloaded and installed the XMRig crypto miner and set it to run automatically at startup. The…

July 29, 2026
Trojanized Zoom/Webex Installers Spread Starland RAT

Trojanized Zoom/Webex Installers Spread Starland RAT

Cisco Talos reports a real, ongoing campaign where a Russian-speaking criminal group tricks people into installing trojanized versions of popular software (like Webex, Zoom, and MobaXterm). Once a victim runs the fake installer, a custom remote-access tool (“Starland RAT”) is installed and used to…

July 16, 2026
Fake AI Apps and Signed Installers Spread Malware

Fake AI Apps and Signed Installers Spread Malware

A large review of “AI-enabled malware” found most samples were proof-of-concepts, but a small set were real threats seen in production environments. The real-world activity included trojanized installers that pretended to be legitimate apps (like a recipe app or a Dropbox installer) and relied on…

August 25, 2026