{
  "hunt": {
    "meta": {
      "tlp": "clear",
      "hunt": {
        "handoff": "promote-to-detection",
        "trigger": "intel-report",
        "methodology": "model-assisted",
        "applicability": "campaign-specific",
        "justification": "Wiper activity causes permanent data loss and significant business disruption. Identifying the staging of these threats during high-interest campaigns like the GTA6 hype cycle protects assets from irreversible damage."
      },
      "name": "GTA6 Malicious Installer and Chaos Wiper Activity",
      "type": "investigation",
      "labels": [
        "hunt",
        "attack.t1190",
        "attack.t1486",
        "attack.t1490"
      ],
      "series": {
        "slug": "grand-theft-auto-vi-hype-leads-to-malware",
        "index": 1,
        "title": "Grand Theft Auto VI hype leads to malware",
        "total": 2
      },
      "related": [
        {
          "hunt": "rat-c2-and-tunneling",
          "reason": "Network-based detection of NJRAT and DCRAT C2 to AWS and ngrok is handled in a separate network-focused hunt.",
          "relation": "out-of-scope-alternative"
        },
        {
          "hunt": "infostealer-credential-theft",
          "reason": "The collection of browser credentials and Discord tokens by Mercurial Grabber is tracked in an identity-focused hunt.",
          "relation": "out-of-scope-alternative"
        }
      ],
      "targets": {
        "hunter": {
          "name": "Hunt agent",
          "agent": true
        },
        "analyst": {
          "name": "Tier-2 analyst",
          "role": "analyst"
        },
        "endpoint": {
          "name": "Endpoint telemetry (hb_ surfaces)",
          "category": "endpoint",
          "telemetry": [
            "endpoint"
          ]
        }
      },
      "analysis": "A single detection rule on vssadmin or bcdedit lacks the context of the social engineering lure. This hunt connects the fake installer lead to rare binaries and final wiper impact, providing a complete behavioral chain that simple rules cannot synthesize.",
      "coverage": [
        {
          "stage": "initial-access-seo-poisoning",
          "steps": [
            "installer-execution-lead"
          ],
          "status": "covered"
        },
        {
          "stage": "fake-installer-deployment",
          "steps": [
            "installer-execution-lead",
            "rare-binaries-in-temp"
          ],
          "status": "covered"
        },
        {
          "stage": "wiper-impact-and-recovery-inhibition",
          "steps": [
            "wiper-impact-evidence"
          ],
          "status": "covered"
        },
        {
          "stage": "rat-c2-and-tunneling",
          "reason": "Belongs to another part of the 'Grand Theft Auto VI hype leads to malware' series.",
          "status": "out_of_scope"
        },
        {
          "stage": "infostealer-credential-theft",
          "reason": "Belongs to another part of the 'Grand Theft Auto VI hype leads to malware' series.",
          "status": "out_of_scope"
        }
      ],
      "scenario": {
        "stages": [
          {
            "name": "Initial Access via SEO Poisoning",
            "slug": "initial-access-seo-poisoning",
            "tactic": "initial-access",
            "techniques": [
              "T1190"
            ],
            "observables": [
              "gta6installer.exe",
              "https://clck.ru/34uJnp",
              "Large ISO files masquerading as GTA6"
            ]
          },
          {
            "name": "Fake Installer Execution and Staging",
            "slug": "fake-installer-deployment",
            "tactic": "execution",
            "observables": [
              "%TEMP%\\checkinternetconnection.bat",
              "%TEMP%\\find.vbs",
              "%TEMP%\\licensechecker.exe",
              "%TEMP%\\rockstar.exe",
              "%TEMP%\\steam.exe",
              "%TEMP%\\rockstargames.exe",
              "%TEMP%\\YandexPackLoader.exe",
              "C:\\Windows\\System32\\drivers\\etc\\hosts",
              "WScript.exe find.vbs"
            ]
          },
          {
            "name": "RAT Command and Control with Tunneling",
            "slug": "rat-c2-and-tunneling",
            "tactic": "command-and-control",
            "techniques": [
              "T1090.003",
              "T1572"
            ],
            "observables": [
              "7.tcp.eu.ngrok.io:12684",
              "35.157.111.131",
              "3.68.56.232",
              "3.67.15.169",
              "a0700877.xsph.ru",
              "141.8.197.42",
              "any.ran.exe",
              "UserOOBEBroker.exe"
            ]
          },
          {
            "name": "Infostealer Collection and Exfiltration",
            "slug": "infostealer-credential-theft",
            "tactic": "credential-access",
            "techniques": [
              "T1555",
              "T1115"
            ],
            "observables": [
              "adminapp.exe",
              "Mercurial Grabber",
              "https://discord.com/api/webhooks/995445114254139543/NmpxQmuBCD6sm3UkVvupGtx-Y0M_A86oJHp00O-l8F4jakfVhqFXzMBoy1uBDdj2rBLc"
            ]
          },
          {
            "name": "Wiper Impact and Recovery Inhibition",
            "slug": "wiper-impact-and-recovery-inhibition",
            "tactic": "impact",
            "techniques": [
              "T1486",
              "T1490"
            ],
            "observables": [
              "gta6.exe",
              "%USERPROFILE%\\AppData\\Roaming\\svchost.exe",
              "vssadmin.exe delete shadows /all /quiet",
              "bcdedit /set {default} recoveryenabled No",
              "read_it.txt",
              "YOU HAVE BEEN HACKED BY THE ASHA HACKER TEAM!"
            ]
          }
        ],
        "summary": "Threat actors are exploiting Grand Theft Auto VI hype by distributing malicious ISO files via SEO poisoning and gaming forums. The infection chain uses a fake installer to deploy a variety of malware including NJRAT, DCRAT, Mercurial Grabber, and Chaos ransomware, which acts as a wiper to destroy user data while inhibiting system recovery."
      },
      "severity": "high",
      "rationale": "The hunt scopes to Windows endpoints using software inventory. Focus on hosts where users have administrative privileges, as the wiper requires them to run its destructive payload.",
      "guardrails": {
        "claims": "no_unsupported",
        "evidence": "citation_required",
        "telemetry": "untrusted",
        "missing_data": "not_benign"
      },
      "hypothesis": "An intruder is exploiting GTA6 hype to deploy a fake installer that stages multiple RATs and executes a destructive wiper masquerading as ransomware.",
      "parameters": {
        "scope_hosts": {
          "from": {
            "ref": "analyst-input",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "list[host]",
          "default": [],
          "description": "Limit the hunt to these hostnames; leave empty for the full estate."
        },
        "lookback_days": {
          "from": {
            "ref": "standard-retention",
            "kind": "manual",
            "observed": "2024-01-01"
          },
          "type": "number",
          "default": "14",
          "description": "Days of history to examine."
        },
        "installer_names": {
          "from": {
            "ref": "huntress-gta6-malware",
            "kind": "article",
            "observed": "2026-09-09"
          },
          "type": "list[string]",
          "default": [
            "gta6installer.exe",
            "licensechecker.exe",
            "rockstargames.exe",
            "rockstargamescrashfixer.exe",
            "rockstarservices.exe",
            "license.exe",
            "adminapp.exe",
            "gta6.exe"
          ],
          "description": "Filenames associated with the fake GTA6 installers and launchers."
        },
        "ransom_note_name": {
          "from": {
            "ref": "huntress-gta6-malware",
            "kind": "article",
            "observed": "2026-09-09"
          },
          "type": "string",
          "default": "read_it.txt",
          "description": "The ransom note filename dropped by the Chaos wiper."
        }
      },
      "provenance": {
        "authors": [
          {
            "org": "huntbase.io",
            "name": "Huntbase hunt generation"
          }
        ],
        "generated": {
          "by": "huntbase-hunt-generation",
          "from": "https://www.huntress.com/blog/fake-gta6-download-malware-analysis",
          "gates": [
            "dry-run",
            "lint"
          ],
          "model": "hb_google/gemini-3-flash-preview"
        }
      },
      "references": [
        {
          "url": "https://www.huntress.com/blog/fake-gta6-download-malware-analysis",
          "name": "Huntress \u2014 Grand Theft Auto VI hype leads to malware"
        }
      ],
      "blind_spots": [
        {
          "id": "no-process-telemetry",
          "risk": "Without command lines, the hunt relies on installer filenames which can be easily randomized, missing behavioral staging leads.",
          "stage": "initial-access-seo-poisoning",
          "question": "whether the connectivity check batch file was executed",
          "requires": "hb_process_activity with command-line logging"
        },
        {
          "id": "no-file-telemetry",
          "risk": "Missing file creation events means we cannot confirm successful wiper impact versus a blocked or failed execution.",
          "stage": "wiper-impact-and-recovery-inhibition",
          "question": "whether the read_it.txt note was created",
          "requires": "hb_file_activity with file creation events"
        },
        {
          "id": "ephemeral-staging-scripts",
          "risk": "The malware often deletes its own staging files; short telemetry retention may lose the evidence of deployment before the hunt runs.",
          "stage": "fake-installer-deployment",
          "question": "whether staging scripts like P3usMXh1h4.bat were deleted",
          "requires": "hb_file_activity deletion logging"
        }
      ]
    },
    "name": "GTA6 Malicious Installer and Chaos Wiper Activity",
    "description": "This hunt identifies the deployment of fake GTA6 installers and the subsequent impact of the Chaos wiper family. It uses a gated flow to first find behavioral leads\u2014like the execution of connectivity-check scripts or known malicious filenames\u2014before fanning out to confirm the presence of rare staged binaries in user temp folders and the creation of ransom notes. This multi-surface synthesis distinguishes successful destructive infections from blocked attempts."
  },
  "nodes": [
    {
      "id": "hypothesis",
      "type": "hypothesis",
      "label": "Hypothesis",
      "config": {
        "tags": [],
        "series": {
          "slug": "grand-theft-auto-vi-hype-leads-to-malware",
          "index": 1,
          "title": "Grand Theft Auto VI hype leads to malware",
          "total": 2
        },
        "coverage": [
          {
            "stage": "initial-access-seo-poisoning",
            "steps": [
              "installer-execution-lead"
            ],
            "status": "covered"
          },
          {
            "stage": "fake-installer-deployment",
            "steps": [
              "installer-execution-lead",
              "rare-binaries-in-temp"
            ],
            "status": "covered"
          },
          {
            "stage": "wiper-impact-and-recovery-inhibition",
            "steps": [
              "wiper-impact-evidence"
            ],
            "status": "covered"
          },
          {
            "stage": "rat-c2-and-tunneling",
            "reason": "Belongs to another part of the 'Grand Theft Auto VI hype leads to malware' series.",
            "status": "out_of_scope"
          },
          {
            "stage": "infostealer-credential-theft",
            "reason": "Belongs to another part of the 'Grand Theft Auto VI hype leads to malware' series.",
            "status": "out_of_scope"
          }
        ],
        "rationale": "An intruder is exploiting GTA6 hype to deploy a fake installer that stages multiple RATs and executes a destructive wiper masquerading as ransomware.",
        "blind_spots": [
          {
            "id": "no-process-telemetry",
            "risk": "Without command lines, the hunt relies on installer filenames which can be easily randomized, missing behavioral staging leads.",
            "stage": "initial-access-seo-poisoning",
            "question": "whether the connectivity check batch file was executed",
            "requires": "hb_process_activity with command-line logging"
          },
          {
            "id": "no-file-telemetry",
            "risk": "Missing file creation events means we cannot confirm successful wiper impact versus a blocked or failed execution.",
            "stage": "wiper-impact-and-recovery-inhibition",
            "question": "whether the read_it.txt note was created",
            "requires": "hb_file_activity with file creation events"
          },
          {
            "id": "ephemeral-staging-scripts",
            "risk": "The malware often deletes its own staging files; short telemetry retention may lose the evidence of deployment before the hunt runs.",
            "stage": "fake-installer-deployment",
            "question": "whether staging scripts like P3usMXh1h4.bat were deleted",
            "requires": "hb_file_activity deletion logging"
          }
        ],
        "scoping_notes": "The hunt scopes to Windows endpoints using software inventory. Focus on hosts where users have administrative privileges, as the wiper requires them to run its destructive payload.",
        "beyond_detection": "A single detection rule on vssadmin or bcdedit lacks the context of the social engineering lure. This hunt connects the fake installer lead to rare binaries and final wiper impact, providing a complete behavioral chain that simple rules cannot synthesize."
      }
    },
    {
      "id": "scope-windows-hosts",
      "type": "query",
      "label": "Scope to Windows hosts",
      "config": {
        "dsl": "sqlite",
        "role": "scoping",
        "source": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%windows%' AND LOWER(vendor_name) LIKE '%microsoft%'",
        "surface": "hb_software_inventory",
        "description": "Identify Windows systems in the estate that are the target of this malware campaign.",
        "expected_signal": "A list of hostnames to focus the behavioral queries."
      },
      "parents": [
        {
          "id": "hypothesis"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "scoping",
        "label": "Scope to Windows hosts",
        "reads": [
          "device_hostname",
          "package_name",
          "vendor_name"
        ],
        "source": "hb_software_inventory",
        "target": "endpoint",
        "content": "SELECT DISTINCT device_hostname FROM hb_software_inventory WHERE LOWER(package_name) LIKE '%windows%' AND LOWER(vendor_name) LIKE '%microsoft%'",
        "silence": "not_evidence_of_absence",
        "expected": "A list of hostnames to focus the behavioral queries.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "installer-execution-lead",
      "type": "query",
      "label": "Detect installer execution lead",
      "config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "source": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{installer_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_cmd_line) LIKE '%checkinternetconnection.bat%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_process_activity",
        "description": "Find the initial execution of the fake GTA6 installer or its connectivity-check script.",
        "expected_signal": "Processes matching the reported filenames or the specific batch script lead."
      },
      "parents": [
        {
          "id": "scope-windows-hosts"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "detection-candidate",
        "label": "Detect installer execution lead",
        "reads": [
          "device_hostname",
          "process_name",
          "process_cmd_line",
          "user_name",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, process_name, process_cmd_line, user_name, time FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (instr(',' || '{{installer_names}}' || ',', ',' || LOWER(process_name) || ',') > 0 OR LOWER(process_cmd_line) LIKE '%checkinternetconnection.bat%') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Processes matching the reported filenames or the specific batch script lead.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "evaluate-lead",
      "type": "analytic",
      "label": "Evaluate installer lead",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "installer-execution-lead"
        ],
        "objective": "Determine if the identified process execution matches the fake GTA6 installer behavior reported by Huntress.",
        "description": "Assess whether the identified process activity warrants the execution of more expensive corroboration queries.",
        "max_iterations": 3,
        "expected_signal": "A per-host verdict of suspicious or benign based on the lead query results.",
        "success_criteria": "A verdict citing specific rows for each host."
      },
      "parents": [
        {
          "id": "installer-execution-lead"
        }
      ]
    },
    {
      "id": "gate-on-lead",
      "type": "checkpoint",
      "label": "Gate on installer lead",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the evaluate-lead verdict is suspicious for at least one host",
        "condition": "the evaluate-lead verdict is suspicious for at least one host",
        "blind_spot": "no-process-telemetry",
        "confidence": "high",
        "description": "Route suspicious hosts to the fan-out corroboration queries.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "evaluate-lead"
        }
      ]
    },
    {
      "id": "rare-binaries-in-temp",
      "type": "query",
      "label": "Rare binaries in user temp folders",
      "config": {
        "dsl": "sqlite",
        "role": "baseline",
        "source": "endpoint",
        "content": "SELECT LOWER(process_path) AS path, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_path) LIKE '%\\temp\\%' OR LOWER(process_path) LIKE '%\\appdata\\roaming\\%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY LOWER(process_path) HAVING host_count <= 3 ORDER BY host_count ASC",
        "surface": "hb_process_activity",
        "description": "Identify RATs and secondary payloads staged in writable user directories.",
        "expected_signal": "A list of binaries that are rare across the fleet and executing from temporary paths."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "baseline",
        "label": "Rare binaries in user temp folders",
        "reads": [
          "process_path",
          "device_hostname",
          "time"
        ],
        "source": "hb_process_activity",
        "target": "endpoint",
        "content": "SELECT LOWER(process_path) AS path, COUNT(DISTINCT device_hostname) AS host_count, MIN(time) AS first_seen FROM hb_process_activity WHERE (LOWER(process_path) LIKE '%\\temp\\%' OR LOWER(process_path) LIKE '%\\appdata\\roaming\\%') AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY LOWER(process_path) HAVING host_count <= 3 ORDER BY host_count ASC",
        "silence": "not_evidence_of_absence",
        "baseline": {
          "window": "{{lookback_days}}d",
          "compare": "first_seen"
        },
        "expected": "A list of binaries that are rare across the fleet and executing from temporary paths.",
        "verified": "dry-run",
        "prevalence": {
          "by": "device_hostname",
          "key": [
            "process_path"
          ],
          "rare_below": 4
        },
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "wiper-impact-evidence",
      "type": "query",
      "label": "Chaos wiper impact evidence",
      "config": {
        "dsl": "sqlite",
        "role": "triage",
        "source": "endpoint",
        "content": "SELECT device_hostname, file_name, file_path, process_name, time FROM hb_file_activity WHERE LOWER(file_name) = LOWER('{{ransom_note_name}}') AND time >= datetime('now', '-{{lookback_days}} days')",
        "surface": "hb_file_activity",
        "description": "Locate the read_it.txt ransom note to confirm successful destructive activity.",
        "expected_signal": "Evidence of ransom note creation across multiple user directories."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_supports"
        }
      ],
      "primitive_config": {
        "dsl": "sqlite",
        "role": "triage",
        "label": "Chaos wiper impact evidence",
        "reads": [
          "device_hostname",
          "file_name",
          "file_path",
          "process_name",
          "time"
        ],
        "source": "hb_file_activity",
        "target": "endpoint",
        "content": "SELECT device_hostname, file_name, file_path, process_name, time FROM hb_file_activity WHERE LOWER(file_name) = LOWER('{{ransom_note_name}}') AND time >= datetime('now', '-{{lookback_days}} days')",
        "silence": "not_evidence_of_absence",
        "expected": "Evidence of ransom note creation across multiple user directories.",
        "verified": "dry-run",
        "verified_at": "2026-09-20"
      }
    },
    {
      "id": "triage-synthesis",
      "type": "analytic",
      "label": "Synthesize infection verdict",
      "config": {
        "cite": "required",
        "tools": [
          "endpoint"
        ],
        "context": [
          "evaluate-lead",
          "rare-binaries-in-temp",
          "wiper-impact-evidence"
        ],
        "objective": "Determine if the host is actively compromised by the fake GTA6 payloads and whether wiper destruction has occurred.",
        "description": "Combine the initial lead with staging behavior and impact evidence to confirm a complete compromise.",
        "max_iterations": 5,
        "expected_signal": "A comprehensive verdict per host citing the installer, staged RATs, and wiper impact.",
        "success_criteria": "A malicious verdict for any host where the installer lead is followed by rare temp binaries or wiper artifacts."
      },
      "parents": [
        {
          "id": "rare-binaries-in-temp",
          "kind": "merge"
        },
        {
          "id": "wiper-impact-evidence",
          "kind": "merge"
        }
      ]
    },
    {
      "id": "route-on-verdict",
      "type": "checkpoint",
      "label": "Route on final verdict",
      "config": {
        "fuzzy": true,
        "judge": "hunter",
        "question": "the triage-synthesis verdict is malicious for at least one host",
        "condition": "the triage-synthesis verdict is malicious for at least one host",
        "blind_spot": "no-file-telemetry",
        "confidence": "high",
        "description": "Direct confirmed infections to containment and analysts for review.",
        "checkpoint_type": "mandatory"
      },
      "parents": [
        {
          "id": "triage-synthesis"
        }
      ]
    },
    {
      "id": "isolate-endpoint",
      "type": "action",
      "label": "Isolate infected endpoint",
      "config": {
        "target": "endpoint",
        "description": "Prevent further data destruction and halt C2 activity from staged RATs.",
        "instructions": "Isolate the host immediately. The Chaos wiper irreversibly overwrites files larger than 200MB. Recovery requires reimaging and restoring from backups.",
        "action_approval": "required"
      },
      "parents": [
        {
          "id": "route-on-verdict",
          "branch": "on_supports"
        }
      ]
    },
    {
      "id": "analyst-manual-review",
      "type": "task",
      "label": "Analyst manual review",
      "config": {
        "assignee": "analyst",
        "description": "Review evidence for suspicious hosts and verify the extent of the impact.",
        "instructions": "Review the cited telemetry. Check for vssadmin.exe execution or desktop wallpaper changes to SpongeBob if process command lines are available. Verify the user who ran the installer and assess for potential lateral movement."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "default"
        },
        {
          "id": "gate-on-lead",
          "branch": "on_unavailable"
        },
        {
          "id": "route-on-verdict",
          "branch": "default"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_unavailable"
        },
        {
          "id": "isolate-endpoint"
        }
      ]
    },
    {
      "id": "close-out",
      "type": "task",
      "label": "Close out",
      "config": {
        "assignee": "analyst",
        "description": "Finalize findings and document hunt results.",
        "instructions": "Document the number of successful compromises versus blocked attempts. Note any blind spots where staging scripts were deleted before collection."
      },
      "parents": [
        {
          "id": "gate-on-lead",
          "branch": "on_refutes"
        },
        {
          "id": "route-on-verdict",
          "branch": "on_refutes"
        },
        {
          "id": "analyst-manual-review"
        }
      ]
    }
  ]
}