Asha Hacker Team is the name used in the desktop-waller message of a destructive malware campaign distributed through fraudulent Grand Theft Auto VI downloads. The operation uses oversized, junk-padded ISO images promoted through search-engine poisoning, gaming forums, social media, and torrent sites, targeting prospective players with a Russian-language fake installer. The installer deploys NJRAT and DCRAT remote-access trojans, Mercurial Grabber, and a Chaos ransomware variant. The remote-access and infostealer components support remote system control, command execution, keylogging, webcam and desktop access, browser credential and cookie theft, theft of gaming-platform sessions and Discord tokens, cryptocurrency-related data theft, system discovery, screenshot capture, and data exfiltration. The Chaos payload functions primarily as a wiper: when executed with administrative privileges, it removes recovery mechanisms, encrypts smaller files, irreversibly overwrites larger files, and leaves a note without a viable payment mechanism. Russian-language lures and installation of Yandex Browser indicate that Russian-speaking users were likely a primary intended audience, but the group’s identity, origin, and any state affiliation are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named in the defacement wallpaper left by a destructive fake-GTA6 installer campaign. The campaign uses fraudulent GTA6 ISO installers as a lure and deploys remote-access trojans, an infostealer, and a Chaos ransomware variant configured as a wiper.
Purportedly responsible for an opportunistic GTA6-themed malware campaign that distributes a fake game ISO. The ISO deploys multiple remote-access trojans, an infostealer, and Chaos ransomware used as a destructive wiper rather than for conventional ransom collection. Attribution is limited to the payload's self-identifying wallpaper message.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.