Since its release in October, Battlefield 6 has garnered a ton of attention, becoming one of the most anticipated gaming releases of the year. However, that publicity hasn't gone unnoticed by the cybercriminal world. Aiming to capitalize on players' impatience, crafty hackers have created fake "cracked" versions of the game, as well as fake trainers that are distributed on torrent sites and underground forums.

The fake versions are released under names that refer to well-known cracking groups, such as InsaneRamZes and RUNE, attempting to gain users' trust through impersonation. This tactic is common in phishing and malware campaigns, but its connection to such a popular game increases the possibility of mass infections.
See also: Shai-Hulud v2 campaign expands from npm to Maven
Three different threats – One common goal: data theft
Cybersecurity researchers at Bitdefender Labs analyzed dozens of samples from these malicious campaigns and identified three distinct forms of malware being used in parallel. Although they are presented as Battlefield 6 installers or ISO files, none of them contain actual game content.
The first sample appears as “Battlefield 6 Trainer Installer” and is aimed entirely at data theft. In fact, experts point out that the malicious file even appears on the second page of Google searches — which increases its exposure to less careful users.
Extracting sensitive information and sending it to insecure servers
Once executed, the malware scans system folders and browser profiles to extract:
- data from crypto wallets
- login cookies from Chrome, Edge, Firefox
- tokens and credentials from Discord
- data from crypto extensions such as iWallet, Yoroi
The information is sent unencrypted to a server with IP 198.251.84.9, which indicates a lack of professionalism but makes the attack extremely dangerous due to the simplicity and speed of data extraction.
See also: Malicious Prettier extension in VSCode Marketplace distributes Anivia Stealer

Advanced techniques from second malware variant
The second variant, named “Battlefield 6.GOG-InsaneRamZes”, features a more sophisticated architecture. It is not a simple infostealer: it includes sophisticated detection evasion techniques, such as:
- geo-blocking in Russia and CIS countries
- Windows hashing API, which hides functions from analysis tools
- anti-sandbox behaviors, e.g. time checks to detect virtual environments
Memory analysis showed that the samples contain references to development tools such as Postman and BitBucket , suggesting that developer credentials are a potential target — which significantly increases the risk.
ISO file that acts as a backdoor with C2 communication
The third sample, which is presented as a full Battlefield 6 ISO, installs a stable remote control. The 25 MB executable decompresses hidden data and creates the file “2GreenYellow.dat”, which it silently executes via regsvr32.exe — a technique often used to bypass antivirus.
See also: RomCom: SocGholish Fake Update attacks to distribute Mythic Agent
The malware repeatedly attempts to connect to a domain that uses Google infrastructure (ei-in-f101.1e100.net), likely to mask C2 traffic (command-and-control) within legitimate online activity. This type of infrastructure allows attackers to execute commands remotely and potentially deploy additional malicious payloads.

What gamers should watch out for
The case reminds us that searching for cracked games, mods, or trainers is one of the most common ways to get infected. And with a title as popular as Battlefield 6, the chances of infection increase dramatically.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Experts recommend:
- download games and tools only from official platforms
- avoiding torrent sites and crack forums
- use of updated antivirus
- checking ISO or .exe files before execution
Bitdefender warns that the campaigns are still ongoing, and new variants with even more advanced functionality may appear.
