Fake GTA 6 Demo Sites Push Password Stealer

Malwarebytes · Medium sophistication
Last updated August 25, 2026

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved passwords and browser session cookies.

How the attack worked

Attackers built a network of websites impersonating Rockstar Games that surfaced in search results for people looking for a GTA 6 demo. The sites used copied official artwork and a Play Now or Official Download button to appear legitimate. Clicking through led victims to download a file named gta6_installer.exe, which was not a game demo at all but a Vidar infostealer designed to harvest saved browser passwords, cookies, and authenticated sessions.

Why it succeeded

The campaign relied on timing and hype rather than technical sophistication. Rockstar has not announced or released a demo of Grand Theft Auto VI, but the sites exploited public anticipation and search behavior around the topic. Attackers can buy advertisements and optimize malicious pages for exactly the terms people search during major news events, placing fraudulent content directly in front of eager users who are less likely to scrutinize a download before running it.

What to watch for

  • Any download claiming to be an unreleased demo, beta, or early build of a well-known game or product
  • A tiny executable file size for something supposedly containing a full game, such as the 1.1 MB installer used here
  • Search results or ads that promise exclusive or early access tied to trending news
  • Domains with slight variations on the official brand name, similar to the gta6demo and rockstar-gta-6 domains identified in this case

How to build resistance

Organizations and individuals can reduce risk from this type of attack by treating unreleased or unofficial download offers as suspicious by default and verifying claims through the publisher's official channels before downloading anything. Security awareness efforts should reinforce that search results and ads are not inherently trustworthy, especially during high-interest news cycles. If a stealer infection is suspected, resetting passwords alone is not sufficient; affected users should also sign out everywhere, revoke active sessions, and remove unfamiliar devices from their accounts to neutralize any stolen session cookies. This scenario is particularly relevant to general employees who may browse gaming or entertainment content on work or personal devices, as well as marketing and communications staff who monitor trending topics and could encounter these lures while researching public interest around a major release.

Key findings

  • Fake GTA 6 “demo” sites impersonate Rockstar and appear in search results for a GTA 6 demo.
  • A Google result advertised an “Official Download,” but the sites deliver a malicious file named `gta6_installer.exe`.
  • The downloaded file is a Vidar infostealer that targets saved passwords, cookies, and authenticated browser sessions.
  • Stolen session cookies can allow account access even if the victim uses 2FA, because the attacker may reuse an already-authenticated session.
  • Known distribution domains include `gta6demo[.]asia`, `gta6demo[.]eu`, `gta6demo[.]us`, and `rockstar-gta-6[.]com`.

Who’s being targeted

  • Commonly targeted roles: All employees, Security awareness program participants, Helpdesk/IT support, Marketing/Comms.
  • Affected industries: Gaming, Media & Entertainment, Consumers/General Public.
  • Attack channels: website.
  • Impersonated: Rockstar Games.

Red flags to watch for

  • A 'demo' is offered even though Rockstar has not announced one
  • The download is a tiny 1.1 MB executable for a supposed AAA game
  • The site uses copied official artwork to look legitimate
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake GTA 6 demo attack work?

Fake sites impersonating Rockstar Games appear in search results for a GTA 6 demo, using Play Now or Official Download buttons that lead victims to download gta6_installer.exe, which is actually a Vidar infostealer.

What data does the malware steal?

The infostealer targets saved passwords, browser cookies, and authenticated browser sessions rather than delivering any actual game content.

Is changing my password enough after this kind of infection?

No, changing a password alone may not be enough because stolen session cookies can let an attacker reuse an already-authenticated session even with 2FA in place. Users should also sign out everywhere and revoke active sessions.

What are the warning signs of this scam?

Red flags include an unannounced demo being offered, a suspiciously tiny 1.1 MB executable claiming to be an AAA game, and use of copied official artwork to appear legitimate.

Read the video transcript

You Google “GTA 6 demo” and see an “Official Download” with Rockstar logos right at the top. Looks legit, right? But that click takes you to gta6demo.asia with a big “Play Now” button. The download is gta6_installer.exe, only 1.1 megabytes. That’s not a demo, it’s Vidar infostealer quietly grabbing your saved passwords and browser cookies. Here’s the nasty part: with those stolen session cookies, someone can open your accounts as if they’re already logged in, even if you use 2FA. Changing your password alone might not kick them out. If you ever downloaded a “GTA 6 demo” or tiny gta6_installer.exe, tell IT now so they can wipe the infostealer and force sign-out on all your accounts.

Similar attacks

Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to trick people into installing credential and crypto-stealing malware, and another uses hundreds of imposter GitHub repositories to lure…

July 17, 2026
Fake Verification Pages Push PavinLoader Malware

Fake Verification Pages Push PavinLoader Malware

Malwarebytes reports that a multi-stage Windows malware loader called PavinLoader is being delivered through multiple real-world campaigns, including ClickFix “verification” pages and fake software downloads. Victims are tricked into running installers or scripts that use legitimate Windows tools…

August 24, 2026
Fake Conferences Fuel OAuth and WhatsApp Phish

Fake Conferences Fuel OAuth and WhatsApp Phish

Google tracked three suspected Russia-linked groups running targeted phishing that abuses real login and authentication features (app passwords, OAuth, and device codes) to get into accounts. The lures often look like legitimate conference or diplomatic invitations, and some campaigns spoof…

August 21, 2026
Russian Spy Phish Uses Legit OAuth Logins

Russian Spy Phish Uses Legit OAuth Logins

Google says three suspected Russian cyber-espionage groups are running highly targeted phishing campaigns against people in government, academia, defense, and think tanks in the US and Europe. A key theme is abusing legitimate Google/Microsoft OAuth login flows so the outreach looks real, tricking…

August 21, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026