23/07/2024
๐๐๐๐ฒ๐ป๐๐ถ๐ผ๐ป ๐๐ฟ๐ฎ๐ป๐ฑ ๐ง๐ต๐ฒ๐ณ๐ ๐๐๐๐ผ ๐๐ฎ๐ป๐! ๐๐ฎ๐ธ๐ฒ ๐๐ง๐ ๐ฉ๐ ๐๐ฒ๐๐ฎ ๐๐ผ๐๐ป๐น๐ผ๐ฎ๐ฑ ๐๐ถ๐๐๐ฟ๐ถ๐ฏ๐๐๐ฒ๐ ๐ ๐ฎ๐น๐๐ฎ๐ฟ๐ฒ
Grand Theft Auto (GTA) is a household name in gaming, and Rockstar Games, the developer behind GTA, has announced the release of Grand Theft Auto VI in Autumn 2025 for PS5 and Xbox Series, which has got fans all excited.
However, this presents threat actors with the perfect opportunity to exploit fans, with Bitdefender researchers detecting suspicious Facebook ads promoting fake beta versions for free download on PC. Social media users, particularly those following GTA content, might encounter sponsored ads promising early access to a non-existent GTA VI beta.
These ads often showcase tempting features, early release dates, and even include convincing-looking gameplay footage, likely stolen from 2022โs Rockstar data breach and other sources. According to Bitdefenderโs report, between July 16 and 18, researchers came across a page promoting free access to the GTA beta version for the first 100 people through sponsored ads.
This page was running three different ads all using the same message and visuals, targeting people aged 18-65. The malicious domain used in the ad was created on June 27, 2024, and was also hosting another Ethereum scam. Users in Europe, including France, Poland, Romania, Germany, Spain, Hungary, Italy, Greece, the Netherlands, and Sweden, were the primary targets.
Security researcher Andrei Mogageโs analysis revealed that the MSI file downloaded through the Facebook ad impersonated a legitimate GTA VI installer and mimicked the installation process. The file shared similarities with FakeBat loader malware that deployed malicious payloads and PowerShell scripts to download next-stage malware like info-stealers and RATs. Clicking the ad leads to a website mimicking a legitimate download page. Here, a user might be prompted to download an โexclusive beta clientโ or complete a survey to gain access.
These downloads arenโt beta versions; theyโre malware in disguise. It is worth noting that Rockstar Games has not announced a beta program for GTA VI. The three malicious samples available for download from the ads were โbrokenโ and could not execute payloads or exfiltrate data. As of July 19, none of these malicious ads remain active. While the reported malicious ads may be removed, there could be hundreds of such malicious ads currently running on social media, especially Facebook, which is known for approving malicious ads.
In February 2024, Savvy Seahorse, a DNS threat actor, was found using Facebook ads to promote and lure unsuspecting victims into its investment scams. In November 2023, Facebook displayed AI-generated โprovocativeโ ads that spread NodeStealer malware. Back in April 2021, Facebook approved an advertisement that displayed and distributed a Facebook Messenger phishing link.