Within days of the Grand Theft Auto VI leak, a 113GB ISO appeared claiming to be the leaked build.

Testers who examined it report that roughly 99.99% of the file is empty zeroes, padded around a payload of about 50KB.

The padding is the disguise

Work out the ratio and it stops being a curiosity. 113GB is about 118 million kilobytes. To hide 50KB inside it, the attacker generated roughly 2.4 million times more filler than payload.

Nobody does that by accident, and nobody does it to evade a scanner — zeroes compress to nothing and hide nothing. They did it because 113GB is what a modern AAA game weighs.

A 50KB download claiming to be Grand Theft Auto VI is obviously a lie. A 113GB download is credible, takes hours, and by the time it finishes the victim has invested enough that they will run it. The file size is not a technical property here. It is the social engineering.

Then it blinds Defender

The installer disables Windows Defender by whitelisting the entire C: drive — an exclusion covering everything, after which the payload runs unimpeded unless some other antivirus is present. Researchers note it could be ransomware.

This is the fourth time this month we have written the same paragraph in a different costume. SPECTRE unlinks EDR callbacks in the Windows kernel. A signed Defender driver can delete Defender at boot. Weedhack sets its own Defender exclusions. Here it is one exclusion covering the whole disk.

None of these defeat the product. They remove its ability to look, which produces exactly the silence of a clean machine — and a missing alert is indistinguishable from safety.

Adding a Defender exclusion needs administrator rights, so somewhere in this a person clicked through an elevation prompt for an installer they knew was pirated.

The leak manufactured the demand

This is the part worth generalising, because it will happen again with the next release.

An enormous number of people suddenly want a file that does not legitimately exist, know it is circulating, and have no way to authenticate it. That is a near-perfect market for malware: verified demand, no reference copy, and a population that already accepts it is doing something dodgy and therefore will not report the outcome.

The leaker did not distribute this ISO. They created the conditions in which it works — which is worth weighing against a protest framed as being on gamers' behalf.

It is the same structure as the fake Minecraft clients: a real thing people want, an unofficial channel they already use, and a file nobody can verify.

What to do

  • There is no legitimate copy. The game is not out. Any download claiming to be it is either useless or hostile, with no third option.
  • Treat file size as marketing, not evidence. A plausible size is trivially manufactured, and here it was the entire trick.
  • A pirated installer asking for administrator rights is the decision point. Nothing that unpacks a game needs to modify your antivirus settings.
  • Check your Defender exclusions if you have run anything like this — Virus and threat protection settings, exclusions list. A whole-drive exclusion you did not add is a compromise indicator, and it takes a minute to look.
  • If you find one, assume the machine is dirty. Remove the exclusion, then rebuild rather than clean, particularly if ransomware is on the table.
  • Wait for 19 November. It is three months.

What is not established

  • What the payload actually does. Described as possible ransomware; no family named in the reporting we have seen.
  • How many people downloaded it. No figure.
  • Who is distributing it. No attribution, and no reason to think it is connected to the leaker.
  • Whether other fake builds are circulating with different payloads. Likely, but unconfirmed.
  • Whether any genuine build is circulating publicly at all. Claims about leaked builds cannot be independently verified from outside.