Scam sites impersonating GTA 6 are using fake countdown pages, leaked-copy offers, and wallet-draining code to steal cryptocurrency and digital assets from visitors. The campaign combines convincing Rockstar details with deceptive approval requests, region blocking, and reusable drainer infrastructure to target wallets across multiple blockchain networks. #GTA6 #Rockstar #Solana #Phantom
Keypoints
- Scam sites themed around Grand Theft Auto VI have targeted users in three different ways this year: fake early access sales, fake demo/Extended Look pages, and a fake fan countdown site.
- The latest site displays believable GTA 6 information, including a countdown to November 19, a Leonida map, and release details matching Rockstar’s announcements.
- Although it appears to sell a leaked copy for $50 or 1 SOL, the site loads wallet-draining code as soon as a visitor arrives.
- The drainer can target assets across seven blockchain networks and can request either direct transfers or long-term approval access for tokens and NFTs.
- The code profiles visitors, checks wallet balances, reports wallet data to the attacker, and can block users from several CIS countries via a setting named CIS_Protection.
- The page appears to combine a legitimate fan template with added scam sales copy, and the larger drainer infrastructure may be rented or hosted as a service.
- Defensive guidance emphasizes reviewing wallet approval screens carefully, rejecting full-balance transfers or broad permissions, and avoiding any unauthorized GTA 6 offers.
MITRE Techniques
- [T1071.001] Application Layer Protocol: Web Protocols – The site retrieves settings and operates through web-based infrastructure for wallet-draining activity (‘it downloads its settings from the operator’s server’).
- [T1046] Network Service Discovery – The script profiles the victim environment and checks connected wallets and network context before proceeding (‘it checks their holdings across different blockchains’).
- [T1016] System Network Configuration Discovery – It uses the visitor’s IP address to determine country and apply region-based blocking (‘it uses the visitor’s IP address to identify their country’).
- [T1082] System Information Discovery – The drainer collects wallet value, tokens, NFTs, IP address, country, and connection count (‘These include the wallet’s estimated dollar value, its tokens and NFTs, the visitor’s IP address and country’).
- [T1027] Obfuscated Files or Information – The code hides server addresses and suppresses analysis-related messages to make inspection harder (‘conceal its server addresses inside the code’).
- [T1497.001] Virtualization/Sandbox Evasion: System Checks – It can detect automated browsers used by security scanners and interfere with analysis tools (‘It can detect the automated browsers used by security scanners’).
- [T1056.001] Input Capture: Keylogging – The page can trick users into approving malicious wallet actions by presenting deceptive transaction prompts (‘retrieves transactions for the victim to approve’).
- [T1204.002] User Execution: Malicious File – The attack depends on the victim approving a wallet transaction or permission request (‘The danger comes when you approve the transaction or permission request that follows’).
- [T1091] Replication Through Removable Media – Not mentioned.
- [T1110] Brute Force – Not mentioned.
Indicators of Compromise
- [Domains] Drainer infrastructure domains used by the scam pages – centrodigestionedellarapina[.]life, dasunerforschtelandamendederwelt[.]sbs
- [Blockchain address] Solana address used by the page’s inline transfer – 21iWU6FJWJ9FKKz4Jek2CyTh2x1fqs5jawjrNgE3nHjN
- [Blockchain networks] Targeted chains supported by the larger drainer – Ethereum, Polygon, BNB Smart Chain, and 4 more networks
- [Countries] Geo-blocked regions associated with CIS_Protection – Armenia, Russia, and 8 more countries
- [Cryptocurrency references] Payment and asset-targeting context – 1 SOL, Ethereum, and major stablecoins
Read more: https://www.malwarebytes.com/blog/scams/2026/09/fake-gta-6-leaked-copy-drains-your-crypto-wallet