HomeGamingBattlefield 6: Fake versions distribute infostealer

Battlefield 6: Fake versions distribute infostealer

Since its release in October, Battlefield 6 has garnered a ton of attention, becoming one of the most anticipated gaming releases of the year. However, that publicity hasn't gone unnoticed by the cybercriminal world. Aiming to capitalize on players' impatience, crafty hackers have created fake "cracked" versions of the game, as well as fake trainers that are distributed on torrent sites and underground forums.

Battlefield 6

The fake versions are released under names that refer to well-known cracking groups, such as InsaneRamZes and RUNE, attempting to gain users' trust through impersonation. This tactic is common in phishing and malware campaigns, but its connection to such a popular game increases the possibility of mass infections.

See also: Shai-Hulud v2 campaign expands from npm to Maven

Three different threats – One common goal: data theft

Cybersecurity researchers at Bitdefender Labs analyzed dozens of samples from these malicious campaigns and identified three distinct forms of malware being used in parallel. Although they are presented as Battlefield 6 installers or ISO files, none of them contain actual game content.

The first sample appears as “Battlefield 6 Trainer Installer” and is aimed entirely at data theft. In fact, experts point out that the malicious file even appears on the second page of Google searches — which increases its exposure to less careful users.

Extracting sensitive information and sending it to insecure servers

Once executed, the malware scans system folders and browser profiles to extract:

  • data from crypto wallets
  • login cookies from Chrome, Edge, Firefox
  • tokens and credentials from Discord
  • data from crypto extensions such as iWallet, Yoroi

The information is sent unencrypted to a server with IP 198.251.84.9, which indicates a lack of professionalism but makes the attack extremely dangerous due to the simplicity and speed of data extraction.

See also: Malicious Prettier extension in VSCode Marketplace distributes Anivia Stealer

Battlefield 6: Fake versions distribute infostealer

Advanced techniques from second malware variant

The second variant, named “Battlefield 6.GOG-InsaneRamZes”, features a more sophisticated architecture. It is not a simple infostealer: it includes sophisticated detection evasion techniques, such as:

  • geo-blocking in Russia and CIS countries
  • Windows hashing API, which hides functions from analysis tools
  • anti-sandbox behaviors, e.g. time checks to detect virtual environments

Memory analysis showed that the samples contain references to development tools such as Postman and BitBucket , suggesting that developer credentials are a potential target — which significantly increases the risk.

ISO file that acts as a backdoor with C2 communication

The third sample, which is presented as a full Battlefield 6 ISO, installs a stable remote control. The 25 MB executable decompresses hidden data and creates the file “2GreenYellow.dat”, which it silently executes via regsvr32.exe — a technique often used to bypass antivirus.

See also: RomCom: SocGholish Fake Update attacks to distribute Mythic Agent

The malware repeatedly attempts to connect to a domain that uses Google infrastructure (ei-in-f101.1e100.net), likely to mask C2 traffic (command-and-control) within legitimate online activity. This type of infrastructure allows attackers to execute commands remotely and potentially deploy additional malicious payloads.

Battlefield 6: Fake versions distribute infostealer

What gamers should watch out for

The case reminds us that searching for cracked games, mods, or trainers is one of the most common ways to get infected. And with a title as popular as Battlefield 6, the chances of infection increase dramatically.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Experts recommend:

  • download games and tools only from official platforms
  • avoiding torrent sites and crack forums
  • use of updated antivirus
  • checking ISO or .exe files before execution

Bitdefender warns that the campaigns are still ongoing, and new variants with even more advanced functionality may appear.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS