Fake GTA VI 'Build' Uses 113GB of Junk Data to Hide Malware
Attackers are leveraging hype for Rockstar's next title to trick gamers into whitelisting their system drives for a virus.
A fraudulent 113GB ISO file claiming to be a leaked build of Grand Theft Auto VI has begun circulating on torrent sites, targeting eager gamers with a sophisticated social engineering trap. The file is not a game, but a delivery vehicle for malware designed to strip a computer of its primary security defenses.
According to reports from Tom's Hardware, the massive file is almost entirely composed of empty junk data—specifically zeroes—used to pad the size to 113GB. This padding creates a facade of legitimacy, as users assume a modern AAA title of this scale must be enormous. Hidden within this bulk is a piece of malware. Analysis of the decompiled bytecode reveals that the virus uses PowerShell commands to whitelist the entire C:\ drive in Windows Defender and employs "taskkill" commands to shut down active security software.
The Climate of Leaks
This scam emerged in the wake of genuine data breaches involving a hacker known as "Cyberleek." This individual has been releasing gameplay and map data as a protest against Rockstar Games' digital pre-sale policies. The resulting chaos and high demand for leaked content created a fertile environment for bad actors to deploy fake files that look plausible to the untrained eye.
In response to the genuine leaks, parent company Take-Two Interactive has taken aggressive legal action. The company has issued subpoenas to Microsoft and Discord, seeking device IDs of server members to identify and prosecute those responsible for the data breaches.
Why the Tactic Works
The effectiveness of this attack relies on the psychological state of the target audience. Because the anticipation for GTA VI is so extreme, users are more likely to ignore standard security warnings or manually disable antivirus software to ensure the "leak" installs correctly. By matching the expected file size of a massive open-world game, the attackers bypass the immediate suspicion that usually accompanies small, suspicious executable files.
What to Watch
Security experts warn that as the official release date approaches, similar "early access" or "beta build" scams are likely to increase. Users are urged to avoid downloading ISO files from unverified torrent sources, regardless of the file size. While Take-Two continues its legal pursuit of the original leakers, the prevalence of this malware highlights a growing trend of using "bloatware" padding to evade detection and deceive users through perceived legitimacy.