#threatreport #LowCompleteness
Fake GTA 6 leaked copy drains your crypto wallet | 01-09-2026
Source:
malwarebytes.com/blog/scams/…
Key details below ↓
🎯Victims: Cryptocurrency wallet users, Gaming consumers
🏭Industry: Retail, Financial
🌐Geo: Kyrgyzstan, Russia, Uzbekistan, Belarus, Azerbaijan, Armenia, Moldova, Kazakhstan, Tajikistan, Turkmenistan
🤖LLM extracted TTPs:`
T1036, T1119, T1614, T1657
🧨IOCs:
- Domain: 2
- IP: 0
- Url: 0
- Hash: 0
- Email: 0
- BrowserExtension: 0
🪙Crypto: solana, ethereum, arbitrum
🗂️Win API: Polygon
#threatreport:
A fraudulent GTA 6 “leaked copy” website disguised as a fan countdown page deploys cryptocurrency wallet-draining code as soon as visitors access it. The site claims to sell the game and encourages visitors to connect a wallet for cryptocurrency payment. Rather than charging the advertised price, the embedded Solana-focused code checks the wallet balance, leaves only a small amount for transaction fees, and prepares to transfer the remaining funds to an attacker-controlled address.
A separate approximately 2.4 MB JavaScript payload provides broader functionality. It incorporates a legitimate wallet-connection library but adds malicious components that inventory connected wallets, estimate the value of their holdings, report wallet information to the operator, and generate transactions for victims to approve. The payload targets Ethereum, Polygon, BNB Smart Chain, Avalanche, Arbitrum, Base, and Fantom. It can identify major stablecoins and request permissions that may enable immediate cryptocurrency transfers or later movement of tokens and entire NFT collections.
Before prompting users to connect a wallet, the script retrieves configuration data from the attacker’s server. When enabled, it uses the visitor’s IP address to determine their country and checks it against a list including Armenia, Azerbaijan, Belarus, Kazakhstan, Kyrgyzstan, Moldova, Russia, Tajikistan, Turkmenistan, and Uzbekistan.
The drainer profiles victims’ wallets across supported blockchains and sends the operator their estimated dollar value, token and NFT holdings, IP address, country, and wallet connection count. Its use of remotely retrieved operator identifiers, settings, and transaction data indicates a hosted or rented drainer service. The remote infrastructure also allows stolen-fund destinations to be changed without modifying the fraudulent website. Users who connected a wallet should treat it as compromised and avoid cryptocurrency recovery offers that require upfront payment, as these may constitute follow-on scams.