How it works

The offer asks you to review a new game and attaches it as an .iso or .img disk image. On Windows, double-clicking an .iso mounts it as a drive letter, and the .exe hidden inside then runs without the usual "this file came from the internet" warning, because that mark-of-the-web tag does not carry to files sitting inside a mounted image.

Attackers moved to disk images for exactly this reason. The .iso wrapper carries the payload past many mail scanners and past the SmartScreen prompt that would otherwise make you stop. The studio is usually one you cannot find anywhere, or the borrowed name of a real small developer, which is why this pattern often maps to no verifiable brand at all.

The tell-tale signals

What to do

Do not mount the image. A real review build comes as a store key or a launcher link from a developer you can look up, and the terms come first. Delete the attachment and search the studio name independently before replying to anything. If you mounted the image and ran the file inside, treat the machine and your Google account as compromised, and recover from a separate clean device by changing the password, ending all sessions, and reviewing channel access.