A fake Grand Theft Auto VI demo is being used to steal passwords and active browser sessions from people looking for early access.

The campaign turns excitement around game footage and a forthcoming official video into a route for installing an information stealer on Windows devices.

The trap begins with convincing websites that impersonate Rockstar Games and surface in searches for a GTA 6 demo. Their official-looking download and Play Now buttons deliver a malicious executable instead of a game, video, or playable test build.

Malwarebytes identified the campaign and said in a report shared with Cyber Security News (CSN) that the file is a Vidar information stealer.

The activity appeared as public interest intensified after unauthorised gameplay clips and a purported Leonida map began circulating online.

The impact can extend well beyond one gaming account. A successful infection can expose email, social media, shopping, payment and game accounts, while stolen session data may let criminals enter accounts that are already signed in.

One of the fake GTA 6 demo websites impersonating Rockstar Games (Source – Malwarebytes)

That makes the fake demo a risk even for people who use unique passwords and two-factor authentication. The concern is heightened because an infection can remain unnoticed until attackers begin using stolen data elsewhere.

Fake GTA 6 Demo Is Actually Malware

There is no official GTA 6 demo, beta, PC build, or downloadable early version. The genuine extended look is a video event, but scammers copied its promotional artwork and language to make their pages appear credible.

The supposed installer is only 1.1 MB, an immediate warning sign for a modern major-release game. The timing is central to the lure. The malicious sample was first seen on August 19, a day after the fresh leak material began spreading.

Search interest gave criminals a ready audience, much as reported fake game downloads have previously used familiar entertainment brands to conceal credential-stealing software.

Once run, the program does not provide a visible game window or install something a victim would recognise. Researchers found no automatic restart mechanism such as a startup entry, task, or service.

The site copies Rockstar’s genuine Extended Look promo, but adds a fake 'Play Now' button (Source - Malwarebytes)
The site copies Rockstar’s genuine Extended Look promo, but adds a fake ‘Play Now’ button (Source – Malwarebytes)

Instead, it can quietly collect saved logins, session cookies, browsing and download history, autofill information, and credentials held by FTP clients. The sample checked 19 browser targets, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi.

It also searched Thunderbird data and targeted Comet plus the browser component used in Roblox Studio. Vidar is already a familiar threat in gaming lures, as a Vidar cheat campaign showed earlier this year.

Stolen Sessions Raise Account Risks

Passwords are not the only valuable data stored by a browser. A session cookie is a small piece of data that tells a site the user has already completed a login.

If it remains valid after theft, an attacker may be able to reuse it without entering the password or completing a new two-factor check.

That is why a password reset alone may not close the door. The malware launches genuine Chrome, Edge, and Firefox programs in a hidden mode to access protected browser information, then removes temporary folders.

Its approach uses software already trusted to read its own data rather than visibly breaking browser encryption. The malware also contacted Telegram, Pinterest, and Steam Community profiles, which can act as changeable pointers to attacker servers.

One of the fake GTA 6 sites appearing in Google search results alongside legitimate GTA 6 coverage (Source - Malwarebytes)
One of the fake GTA 6 sites appearing in Google search results alongside legitimate GTA 6 coverage (Source – Malwarebytes)

It made observed connections to two malicious destinations. This blend of ordinary-looking web traffic and credential theft mirrors risks explained stolen browser cookies can create when active sessions are replayed.

Anyone who ran the installer should scan the affected computer with a trusted security tool, then use a clean device to change important passwords, beginning with email and financial accounts.

They should sign out of all sessions, remove unfamiliar devices and applications, review recovery details, and watch accounts closely for suspicious activity.

The safer rule is simple: obtain games only from the publisher or established official stores, and treat search ads, leaked builds, and surprise downloads with caution.

Check file sizes before running anything. The account exposure described in a recent Vanta Stealer analysis shows why revoking sessions matters alongside changing credentials.

Indicators of compromise (IoCs):-

Type Indicator Description
Domain gta6demo[.]asia Fake GTA 6 demo distribution site
Domain gta6demo[.]eu Fake GTA 6 demo distribution site
Domain gta6demo[.]us Fake GTA 6 demo distribution site
Domain rockstar-gta-6[.]com Fake GTA 6 demo distribution site
File name gta6_installer.exe Malicious executable delivered by the fake download sites
SHA-256 a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0 Hash of the malicious executable
URL telegram[.]me/m1duus Dead-drop resolver profile URL
URL t[.]me/m1duus Dead-drop resolver profile URL
URL pinterest[.]com/m1duus Dead-drop resolver profile URL
URL steamcommunity[.]com/profiles/76561198657426610 Dead-drop resolver profile URL
Domain ses.1001gacor[.]org Network infrastructure observed in the sample
Domain ket.sm188daftar[.]mom Network infrastructure observed in the sample
Domain ket.1001gacor[.]org Additional Vidar infrastructure
Domain ljr.1001gacor[.]org Additional Vidar infrastructure
Domain nhg.1001gacor[.]org Additional Vidar infrastructure
Domain bob.1001gacor[.]org Additional Vidar infrastructure
Domain kra.1001gacor[.]org Additional Vidar infrastructure
Domain brr.1001gacor[.]org Additional Vidar infrastructure
Domain sto.1001gacor[.]org Additional Vidar infrastructure
Domain rex.1001gacor[.]org Additional Vidar infrastructure
Domain bib.1001gacor[.]org Additional Vidar infrastructure
Domain ges.1001gacor[.]org Additional Vidar infrastructure
Domain tax.11gokil[.]org Additional Vidar infrastructure
Domain sii.11gokil[.]org Additional Vidar infrastructure
Domain zaf.11gokil[.]org Additional Vidar infrastructure
Domain dez.11gokil[.]org Additional Vidar infrastructure
Domain tax.sm188dnsx[.]top Additional Vidar infrastructure
Domain sii.sm188dnsx[.]top Additional Vidar infrastructure
Domain zaf.sm188dnsx[.]top Additional Vidar infrastructure

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.