A fake Grand Theft Auto VI demo is being used to steal passwords and active browser sessions from people looking for early access.
The campaign turns excitement around game footage and a forthcoming official video into a route for installing an information stealer on Windows devices.
The trap begins with convincing websites that impersonate Rockstar Games and surface in searches for a GTA 6 demo. Their official-looking download and Play Now buttons deliver a malicious executable instead of a game, video, or playable test build.
Malwarebytes identified the campaign and said in a report shared with Cyber Security News (CSN) that the file is a Vidar information stealer.
The activity appeared as public interest intensified after unauthorised gameplay clips and a purported Leonida map began circulating online.
The impact can extend well beyond one gaming account. A successful infection can expose email, social media, shopping, payment and game accounts, while stolen session data may let criminals enter accounts that are already signed in.
That makes the fake demo a risk even for people who use unique passwords and two-factor authentication. The concern is heightened because an infection can remain unnoticed until attackers begin using stolen data elsewhere.
Fake GTA 6 Demo Is Actually Malware
There is no official GTA 6 demo, beta, PC build, or downloadable early version. The genuine extended look is a video event, but scammers copied its promotional artwork and language to make their pages appear credible.
The supposed installer is only 1.1 MB, an immediate warning sign for a modern major-release game. The timing is central to the lure. The malicious sample was first seen on August 19, a day after the fresh leak material began spreading.
Search interest gave criminals a ready audience, much as reported fake game downloads have previously used familiar entertainment brands to conceal credential-stealing software.
Once run, the program does not provide a visible game window or install something a victim would recognise. Researchers found no automatic restart mechanism such as a startup entry, task, or service.
.webp)
Instead, it can quietly collect saved logins, session cookies, browsing and download history, autofill information, and credentials held by FTP clients. The sample checked 19 browser targets, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi.
It also searched Thunderbird data and targeted Comet plus the browser component used in Roblox Studio. Vidar is already a familiar threat in gaming lures, as a Vidar cheat campaign showed earlier this year.
Stolen Sessions Raise Account Risks
Passwords are not the only valuable data stored by a browser. A session cookie is a small piece of data that tells a site the user has already completed a login.
If it remains valid after theft, an attacker may be able to reuse it without entering the password or completing a new two-factor check.
That is why a password reset alone may not close the door. The malware launches genuine Chrome, Edge, and Firefox programs in a hidden mode to access protected browser information, then removes temporary folders.
Its approach uses software already trusted to read its own data rather than visibly breaking browser encryption. The malware also contacted Telegram, Pinterest, and Steam Community profiles, which can act as changeable pointers to attacker servers.
.webp)
It made observed connections to two malicious destinations. This blend of ordinary-looking web traffic and credential theft mirrors risks explained stolen browser cookies can create when active sessions are replayed.
Anyone who ran the installer should scan the affected computer with a trusted security tool, then use a clean device to change important passwords, beginning with email and financial accounts.
They should sign out of all sessions, remove unfamiliar devices and applications, review recovery details, and watch accounts closely for suspicious activity.
The safer rule is simple: obtain games only from the publisher or established official stores, and treat search ads, leaked builds, and surprise downloads with caution.
Check file sizes before running anything. The account exposure described in a recent Vanta Stealer analysis shows why revoking sessions matters alongside changing credentials.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Domain | gta6demo[.]asia | Fake GTA 6 demo distribution site |
| Domain | gta6demo[.]eu | Fake GTA 6 demo distribution site |
| Domain | gta6demo[.]us | Fake GTA 6 demo distribution site |
| Domain | rockstar-gta-6[.]com | Fake GTA 6 demo distribution site |
| File name | gta6_installer.exe | Malicious executable delivered by the fake download sites |
| SHA-256 | a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0 | Hash of the malicious executable |
| URL | telegram[.]me/m1duus | Dead-drop resolver profile URL |
| URL | t[.]me/m1duus | Dead-drop resolver profile URL |
| URL | pinterest[.]com/m1duus | Dead-drop resolver profile URL |
| URL | steamcommunity[.]com/profiles/76561198657426610 | Dead-drop resolver profile URL |
| Domain | ses.1001gacor[.]org | Network infrastructure observed in the sample |
| Domain | ket.sm188daftar[.]mom | Network infrastructure observed in the sample |
| Domain | ket.1001gacor[.]org | Additional Vidar infrastructure |
| Domain | ljr.1001gacor[.]org | Additional Vidar infrastructure |
| Domain | nhg.1001gacor[.]org | Additional Vidar infrastructure |
| Domain | bob.1001gacor[.]org | Additional Vidar infrastructure |
| Domain | kra.1001gacor[.]org | Additional Vidar infrastructure |
| Domain | brr.1001gacor[.]org | Additional Vidar infrastructure |
| Domain | sto.1001gacor[.]org | Additional Vidar infrastructure |
| Domain | rex.1001gacor[.]org | Additional Vidar infrastructure |
| Domain | bib.1001gacor[.]org | Additional Vidar infrastructure |
| Domain | ges.1001gacor[.]org | Additional Vidar infrastructure |
| Domain | tax.11gokil[.]org | Additional Vidar infrastructure |
| Domain | sii.11gokil[.]org | Additional Vidar infrastructure |
| Domain | zaf.11gokil[.]org | Additional Vidar infrastructure |
| Domain | dez.11gokil[.]org | Additional Vidar infrastructure |
| Domain | tax.sm188dnsx[.]top | Additional Vidar infrastructure |
| Domain | sii.sm188dnsx[.]top | Additional Vidar infrastructure |
| Domain | zaf.sm188dnsx[.]top | Additional Vidar infrastructure |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.