Cyber Security News

Fake GTA 6 Demo Is Actually Malware That Steals Your Passwords and Logged-In Sessions

A fake Grand Theft Auto VI demo is being used to steal passwords and active browser sessions from people looking for early access.

The campaign turns excitement around game footage and a forthcoming official video into a route for installing an information stealer on Windows devices.

The trap begins with convincing websites that impersonate Rockstar Games and surface in searches for a GTA 6 demo. Their official-looking download and Play Now buttons deliver a malicious executable instead of a game, video, or playable test build.

Malwarebytes identified the campaign and said in a report shared with Cyber Security News (CSN) that the file is a Vidar information stealer.

The activity appeared as public interest intensified after unauthorised gameplay clips and a purported Leonida map began circulating online.

The impact can extend well beyond one gaming account. A successful infection can expose email, social media, shopping, payment and game accounts, while stolen session data may let criminals enter accounts that are already signed in.

One of the fake GTA 6 demo websites impersonating Rockstar Games (Source – Malwarebytes)

That makes the fake demo a risk even for people who use unique passwords and two-factor authentication. The concern is heightened because an infection can remain unnoticed until attackers begin using stolen data elsewhere.

Fake GTA 6 Demo Is Actually Malware

There is no official GTA 6 demo, beta, PC build, or downloadable early version. The genuine extended look is a video event, but scammers copied its promotional artwork and language to make their pages appear credible.

The supposed installer is only 1.1 MB, an immediate warning sign for a modern major-release game. The timing is central to the lure. The malicious sample was first seen on August 19, a day after the fresh leak material began spreading.

Search interest gave criminals a ready audience, much as reported fake game downloads have previously used familiar entertainment brands to conceal credential-stealing software.

Once run, the program does not provide a visible game window or install something a victim would recognise. Researchers found no automatic restart mechanism such as a startup entry, task, or service.

The site copies Rockstar’s genuine Extended Look promo, but adds a fake ‘Play Now’ button (Source – Malwarebytes)

Instead, it can quietly collect saved logins, session cookies, browsing and download history, autofill information, and credentials held by FTP clients. The sample checked 19 browser targets, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi.

It also searched Thunderbird data and targeted Comet plus the browser component used in Roblox Studio. Vidar is already a familiar threat in gaming lures, as a Vidar cheat campaign showed earlier this year.

Stolen Sessions Raise Account Risks

Passwords are not the only valuable data stored by a browser. A session cookie is a small piece of data that tells a site the user has already completed a login.

If it remains valid after theft, an attacker may be able to reuse it without entering the password or completing a new two-factor check.

That is why a password reset alone may not close the door. The malware launches genuine Chrome, Edge, and Firefox programs in a hidden mode to access protected browser information, then removes temporary folders.

Its approach uses software already trusted to read its own data rather than visibly breaking browser encryption. The malware also contacted Telegram, Pinterest, and Steam Community profiles, which can act as changeable pointers to attacker servers.

One of the fake GTA 6 sites appearing in Google search results alongside legitimate GTA 6 coverage (Source – Malwarebytes)

It made observed connections to two malicious destinations. This blend of ordinary-looking web traffic and credential theft mirrors risks explained stolen browser cookies can create when active sessions are replayed.

Anyone who ran the installer should scan the affected computer with a trusted security tool, then use a clean device to change important passwords, beginning with email and financial accounts.

They should sign out of all sessions, remove unfamiliar devices and applications, review recovery details, and watch accounts closely for suspicious activity.

The safer rule is simple: obtain games only from the publisher or established official stores, and treat search ads, leaked builds, and surprise downloads with caution.

Check file sizes before running anything. The account exposure described in a recent Vanta Stealer analysis shows why revoking sessions matters alongside changing credentials.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Domaingta6demo[.]asiaFake GTA 6 demo distribution site
Domaingta6demo[.]euFake GTA 6 demo distribution site
Domaingta6demo[.]usFake GTA 6 demo distribution site
Domainrockstar-gta-6[.]comFake GTA 6 demo distribution site
File namegta6_installer.exeMalicious executable delivered by the fake download sites
SHA-256a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0Hash of the malicious executable
URLtelegram[.]me/m1duusDead-drop resolver profile URL
URLt[.]me/m1duusDead-drop resolver profile URL
URLpinterest[.]com/m1duusDead-drop resolver profile URL
URLsteamcommunity[.]com/profiles/76561198657426610Dead-drop resolver profile URL
Domainses.1001gacor[.]orgNetwork infrastructure observed in the sample
Domainket.sm188daftar[.]momNetwork infrastructure observed in the sample
Domainket.1001gacor[.]orgAdditional Vidar infrastructure
Domainljr.1001gacor[.]orgAdditional Vidar infrastructure
Domainnhg.1001gacor[.]orgAdditional Vidar infrastructure
Domainbob.1001gacor[.]orgAdditional Vidar infrastructure
Domainkra.1001gacor[.]orgAdditional Vidar infrastructure
Domainbrr.1001gacor[.]orgAdditional Vidar infrastructure
Domainsto.1001gacor[.]orgAdditional Vidar infrastructure
Domainrex.1001gacor[.]orgAdditional Vidar infrastructure
Domainbib.1001gacor[.]orgAdditional Vidar infrastructure
Domainges.1001gacor[.]orgAdditional Vidar infrastructure
Domaintax.11gokil[.]orgAdditional Vidar infrastructure
Domainsii.11gokil[.]orgAdditional Vidar infrastructure
Domainzaf.11gokil[.]orgAdditional Vidar infrastructure
Domaindez.11gokil[.]orgAdditional Vidar infrastructure
Domaintax.sm188dnsx[.]topAdditional Vidar infrastructure
Domainsii.sm188dnsx[.]topAdditional Vidar infrastructure
Domainzaf.sm188dnsx[.]topAdditional Vidar infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago