Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Malicious GTA VI ‘113 GB’ Fake Build Distributes Malware that Disables Windows Defender

A 113 GB fake GTA VI build was found to contain a 50 KB malware payload that adds a Windows Defender exclusion for the entire system drive and kills security software. The episode highlights the need for robust security‑awareness training and audit‑ready evidence of user‑education controls.

LiveThreat™ Intelligence · 📅 August 24, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
2 recommended
📰
Source
securityaffairs.com

Malicious GTA VI “113 GB” Fake Build Distributes Malware that Disables Windows Defender

What Happened – Cybercriminals circulated a 113 GB file purporting to be a pre‑release build of Grand Theft Auto VI. The file is almost entirely empty data, with a 50 KB malicious payload that adds a Windows Defender exclusion for the entire system drive and terminates security tools before delivering a second‑stage payload.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a classic social‑engineering attack that bypasses technical controls; SOC 2 ‑ Security – CC6.1 (Logical Access Controls) requires documented awareness training and evidence that users can recognize and report suspicious files.
  • Continuous‑compliance programs must capture security‑awareness training completion and phishing‑simulation results as audit evidence to demonstrate due diligence.
  • The Security Awareness Training capability helps organizations embed measurable training, track user behavior, and produce the artifacts auditors expect for the “Security” trust principle.

Who Is Affected – Gaming & entertainment companies, torrent and file‑sharing platforms, and any organization whose employees or customers may be enticed by high‑profile media leaks.

Recommended Actions

  • Map the incident to SOC 2 CC6.1 and ensure your security‑awareness program includes simulated phishing for “malicious file” scenarios.
  • Collect evidence of training completion, phishing‑test results, and remediation actions as part of your continuous‑monitoring audit trail.
  • Deploy endpoint‑detection rules that flag attempts to add Windows Defender exclusions or terminate security services.

Source: Security Affairs

Technical Notes – The payload uses PowerShell commands (Add‑MpPreference -ExclusionPath %SystemDrive%, taskkill -f) to whitelist the C:\ drive and kill security processes. The malicious code is hidden within a 113 GB file that is 99.99 % zero‑filled, making size a deceptive lure. Source: same as above

📰 Original Source
https://securityaffairs.com/197772/malware/cybercriminals-turn-gta-vi-leaks-into-malware-bait.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Phishing and social engineering are a people-and-policy problem.

The Verisq AI Trust Operations platform pairs Security Awareness Training with policy adoption tracking, so human-risk controls are documented and audit-ready.

Explore the Verisq AI Trust Operations platform →