Fake GTA VI Leak Pushes 113GB Malware Trap

Security Affairs · Medium sophistication
Last updated August 25, 2026

Attackers are abusing excitement around GTA VI leaks by distributing a fake 113GB “playable build” that is mostly empty data with a small malware payload hidden inside. The malware attempts to weaken defenses by adding Windows Defender exclusions and killing security tools, then likely prepares the system for follow-on attacks. Related lures include fake GTA 6 download sites, fake “GTA 6 Mobile” apps, and fake Rockstar Social Club login pages designed to steal credentials.

How the Attack Worked

Attackers capitalized on excitement around a rumored GTA VI leak by promoting a supposed 113GB playable build. In reality, the file was 99.99% empty padding, essentially endless zeroes, wrapped around a tiny 50 KB payload. The large file size served as a disguise, making the download seem legitimate simply due to its scale, while the actual malicious code was small enough to hide easily inside the junk data.

Once executed, the payload contained commands designed to whitelist the entire C: drive in Windows Defender and forcibly kill security software using taskkill. This behavior suggests the malware was meant to weaken a system's defenses as a setup step, likely preparing the device for additional follow-on attacks rather than acting as a complete standalone threat.

Related Lures Using the Same Hype

The fake 113GB build was not an isolated case. Researchers also identified fake GTA 6 websites offering Windows installers that use DLL side-loading to execute malware, a fake GTA 6 Mobile app that redirects to a domain linked to infostealers and ransomware, and fake Rockstar Social Club login pages built to steal account credentials. Together, these lures show attackers targeting different entry points, downloads, mobile apps, and login pages, all tied to the same trending topic.

Why It Succeeded

The timing mattered. Real leak activity around GTA VI was already circulating, which made the fake download feel plausible to users searching for the same content. When real and fake material appear side by side, it becomes harder for people to judge what is safe to download or trust. The combination of a hyped, unreleased game and an oversized file that looked

Key findings

  • A “playable GTA VI build” was promoted as a 113GB download; analysis found it was “99.99% empty” padding with a “tiny 50 KB virus” embedded.
  • The malware included commands intended to weaken endpoint defenses, including adding a Windows Defender exclusion for the system drive and killing security software.
  • Fake GTA 6 downloads reportedly spread via piracy/torrent sites during an active leak cycle, making the lure feel believable.
  • Other related lures include fake GTA 6 websites offering Windows installers, a fake “GTA 6 Mobile” app that redirects to a domain linked to infostealers/ransomware, and fake Rockstar Social Club login pages aimed at stealing credentials.

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Security awareness training participants.
  • Affected industries: Entertainment/Gaming, Consumers/End users, Technology (endpoint security impacted).
  • Attack channels: website.
  • Impersonated: GTA VI leaker/community (implied “leak” source tied to current news), Fake GTA 6 website (implied association with Rockstar/GTA 6), Rockstar Social Club.

Red flags to watch for

  • Unreleased ‘AAA’ game offered as a playable build months early via torrents/piracy sites
  • Unusually massive file size that can be used to hide a small payload
  • Installer behavior that attempts to disable antivirus/endpoint protections
  • Software installer offered from unofficial site rather than a trusted store/publisher
  • Brand-new ‘exclusive’ GTA 6 installer appearing outside official channels
  • Executable installer download tied to a hype-driven event/leak wave
  • Login prompt tied to ‘leaked’/pirated content
  • Untrusted domain or lookalike site for a brand login
  • Pressure/curiosity hook around exclusive access to leak content
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the fake GTA VI leak malware?

Attackers promoted a 113GB file claiming to be a playable GTA VI build, but it was 99.99% empty padding hiding a tiny 50 KB virus designed to weaken endpoint defenses.

How did the malware try to disable security tools?

Decompiled code contained commands to whitelist the entire C: drive in Windows Defender and kill security software using taskkill, effectively disabling antivirus before further attacks could launch.

Are there other GTA 6 related scams besides the fake leak?

Yes, related lures include fake GTA 6 websites offering Windows installers that use DLL side-loading, a fake GTA 6 Mobile app, and fake Rockstar Social Club login pages designed to steal credentials.

Why did this scam seem believable?

Real leak activity around GTA VI was happening at the same time, and mixing real and fake content made it harder for users to distinguish legitimate leaks from bait.

Read the video transcript

If you see a ‘leaked’ 113‑gig GTA VI download, assume it’s a trap, not an early access miracle. Researchers checked one of these files: it was 99.99% empty junk, endless zeroes, with a tiny 50 KB virus inside that tried to whitelist the entire C drive in Windows Defender and kill security tools. Same playbook with fake GTA 6 download sites, a bogus 'GTA 6 Mobile' app, even Rockstar Social Club lookalike logins, malware and credential theft wrapped in leak hype. Here’s the move: if you want GTA or any big-name game, only download and log in through official stores or rockstargames.com, never from torrents, ‘leak’ links, or random promo sites.

Similar attacks

Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Odyssey Piracy Lures Push Fake Fixes and EXE “Movies”

Odyssey Piracy Lures Push Fake Fixes and EXE “Movies”

Scammers quickly set up fake piracy pages for Christopher Nolan’s “The Odyssey” to trick people into either clicking a fake browser “Fix It Now” warning or downloading a “movie” that is actually a Windows program. The goal is to route victims through malicious advertising redirects or get them to…

July 20, 2026
Phish Lures Steal Bank Logins via Telegram

Phish Lures Steal Bank Logins via Telegram

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing…

August 24, 2026
Fake CAPTCHA Tricks Users Into Running Malware

Fake CAPTCHA Tricks Users Into Running Malware

Researchers found a criminal operation (StopAndProtect) that used nearly 2,000 hacked WordPress sites as a delivery network. Visitors were shown a fake CAPTCHA that pressured them to copy and run a PowerShell command, which then installed malware that could steal data, capture screenshots, and…

August 20, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Odyssey Piracy Traps: Fake Alerts and EXE “Movies”

Odyssey Piracy Traps: Fake Alerts and EXE “Movies”

Researchers reported that scammers set up cloned piracy sites within hours of Christopher Nolan’s The Odyssey release to trick people looking for pirated copies. The scams used a fake “Browser Issue Detected” pop-up to push users into malicious ad redirects and a Windows .exe file disguised as a…

July 20, 2026