Fake GTA VI Leak Pushes 113GB Malware Trap

Security Affairs · Medium sophistication
Last updated August 25, 2026

Attackers are abusing excitement around GTA VI leaks by distributing a fake 113GB “playable build” that is mostly empty data with a small malware payload hidden inside. The malware attempts to weaken defenses by adding Windows Defender exclusions and killing security tools, then likely prepares the system for follow-on attacks. Related lures include fake GTA 6 download sites, fake “GTA 6 Mobile” apps, and fake Rockstar Social Club login pages designed to steal credentials.

How the Attack Worked

Attackers capitalized on excitement around a rumored GTA VI leak by promoting a supposed 113GB playable build. In reality, the file was 99.99% empty padding, essentially endless zeroes, wrapped around a tiny 50 KB payload. The large file size served as a disguise, making the download seem legitimate simply due to its scale, while the actual malicious code was small enough to hide easily inside the junk data.

Once executed, the payload contained commands designed to whitelist the entire C: drive in Windows Defender and forcibly kill security software using taskkill. This behavior suggests the malware was meant to weaken a system's defenses as a setup step, likely preparing the device for additional follow-on attacks rather than acting as a complete standalone threat.

Related Lures Using the Same Hype

The fake 113GB build was not an isolated case. Researchers also identified fake GTA 6 websites offering Windows installers that use DLL side-loading to execute malware, a fake GTA 6 Mobile app that redirects to a domain linked to infostealers and ransomware, and fake Rockstar Social Club login pages built to steal account credentials. Together, these lures show attackers targeting different entry points, downloads, mobile apps, and login pages, all tied to the same trending topic.

Why It Succeeded

The timing mattered. Real leak activity around GTA VI was already circulating, which made the fake download feel plausible to users searching for the same content. When real and fake material appear side by side, it becomes harder for people to judge what is safe to download or trust. The combination of a hyped, unreleased game and an oversized file that looked

Key findings

  • A “playable GTA VI build” was promoted as a 113GB download; analysis found it was “99.99% empty” padding with a “tiny 50 KB virus” embedded.
  • The malware included commands intended to weaken endpoint defenses, including adding a Windows Defender exclusion for the system drive and killing security software.
  • Fake GTA 6 downloads reportedly spread via piracy/torrent sites during an active leak cycle, making the lure feel believable.
  • Other related lures include fake GTA 6 websites offering Windows installers, a fake “GTA 6 Mobile” app that redirects to a domain linked to infostealers/ransomware, and fake Rockstar Social Club login pages aimed at stealing credentials.

Who’s being targeted

  • Commonly targeted roles: All employees, IT, Security awareness training participants.
  • Affected industries: Entertainment/Gaming, Consumers/End users, Technology (endpoint security impacted).
  • Attack channels: website.
  • Impersonated: GTA VI leaker/community (implied “leak” source tied to current news), Fake GTA 6 website (implied association with Rockstar/GTA 6), Rockstar Social Club.

Red flags to watch for

  • Unreleased ‘AAA’ game offered as a playable build months early via torrents/piracy sites
  • Unusually massive file size that can be used to hide a small payload
  • Installer behavior that attempts to disable antivirus/endpoint protections
  • Software installer offered from unofficial site rather than a trusted store/publisher
  • Brand-new ‘exclusive’ GTA 6 installer appearing outside official channels
  • Executable installer download tied to a hype-driven event/leak wave
  • Login prompt tied to ‘leaked’/pirated content
  • Untrusted domain or lookalike site for a brand login
  • Pressure/curiosity hook around exclusive access to leak content
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the fake GTA VI leak malware?

Attackers promoted a 113GB file claiming to be a playable GTA VI build, but it was 99.99% empty padding hiding a tiny 50 KB virus designed to weaken endpoint defenses.

How did the malware try to disable security tools?

Decompiled code contained commands to whitelist the entire C: drive in Windows Defender and kill security software using taskkill, effectively disabling antivirus before further attacks could launch.

Are there other GTA 6 related scams besides the fake leak?

Yes, related lures include fake GTA 6 websites offering Windows installers that use DLL side-loading, a fake GTA 6 Mobile app, and fake Rockstar Social Club login pages designed to steal credentials.

Why did this scam seem believable?

Real leak activity around GTA VI was happening at the same time, and mixing real and fake content made it harder for users to distinguish legitimate leaks from bait.

Read the video transcript

If you see a ‘leaked’ 113‑gig GTA VI download, assume it’s a trap, not an early access miracle. Researchers checked one of these files: it was 99.99% empty junk, endless zeroes, with a tiny 50 KB virus inside that tried to whitelist the entire C drive in Windows Defender and kill security tools. Same playbook with fake GTA 6 download sites, a bogus 'GTA 6 Mobile' app, even Rockstar Social Club lookalike logins, malware and credential theft wrapped in leak hype. Here’s the move: if you want GTA or any big-name game, only download and log in through official stores or rockstargames.com, never from torrents, ‘leak’ links, or random promo sites.

Similar attacks

Korea Flags Job-Offer Phish + Watering Holes

Korea Flags Job-Offer Phish + Watering Holes

South Korean agencies warned that a state-backed hacking group is actively targeting citizens and businesses using job-themed phishing emails and “watering hole” attacks on legitimate websites. The phishing lures include fake job applicants sending resume links and impersonated recruiters sending…

July 31, 2026
Odyssey Piracy Lures Push Fake Fixes and EXE “Movies”

Odyssey Piracy Lures Push Fake Fixes and EXE “Movies”

Scammers quickly set up fake piracy pages for Christopher Nolan’s “The Odyssey” to trick people into either clicking a fake browser “Fix It Now” warning or downloading a “movie” that is actually a Windows program. The goal is to route victims through malicious advertising redirects or get them to…

July 20, 2026
Recruiter, RMM, and Vishing Scams Hit Hard

Recruiter, RMM, and Vishing Scams Hit Hard

This weekly roundup includes multiple real-world social-engineering and phishing-style operations, including fake recruiter outreach pushing malicious Android apps, phishing emails that trick users into installing remote management tools, and vishing that reportedly led to compromised Okta…

September 4, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Phish Lures Steal Bank Logins via Telegram

Phish Lures Steal Bank Logins via Telegram

The report describes confirmed phishing activity targeting the financial sector, where victims were tricked into fake login pages via emails, links, or HTML attachments. The credentials entered were then exfiltrated to attackers through Telegram using APIs. The same report also highlights ongoing…

August 24, 2026