Fake GTA 6 Demo Sites Push Password Stealer

Malwarebytes · Medium sophistication
Last updated August 25, 2026

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved passwords and browser session cookies.

How the attack worked

Attackers built a network of websites impersonating Rockstar Games that surfaced in search results for people looking for a GTA 6 demo. The sites used copied official artwork and a Play Now or Official Download button to appear legitimate. Clicking through led victims to download a file named gta6_installer.exe, which was not a game demo at all but a Vidar infostealer designed to harvest saved browser passwords, cookies, and authenticated sessions.

Why it succeeded

The campaign relied on timing and hype rather than technical sophistication. Rockstar has not announced or released a demo of Grand Theft Auto VI, but the sites exploited public anticipation and search behavior around the topic. Attackers can buy advertisements and optimize malicious pages for exactly the terms people search during major news events, placing fraudulent content directly in front of eager users who are less likely to scrutinize a download before running it.

What to watch for

  • Any download claiming to be an unreleased demo, beta, or early build of a well-known game or product
  • A tiny executable file size for something supposedly containing a full game, such as the 1.1 MB installer used here
  • Search results or ads that promise exclusive or early access tied to trending news
  • Domains with slight variations on the official brand name, similar to the gta6demo and rockstar-gta-6 domains identified in this case

How to build resistance

Organizations and individuals can reduce risk from this type of attack by treating unreleased or unofficial download offers as suspicious by default and verifying claims through the publisher's official channels before downloading anything. Security awareness efforts should reinforce that search results and ads are not inherently trustworthy, especially during high-interest news cycles. If a stealer infection is suspected, resetting passwords alone is not sufficient; affected users should also sign out everywhere, revoke active sessions, and remove unfamiliar devices from their accounts to neutralize any stolen session cookies. This scenario is particularly relevant to general employees who may browse gaming or entertainment content on work or personal devices, as well as marketing and communications staff who monitor trending topics and could encounter these lures while researching public interest around a major release.

Key findings

  • Fake GTA 6 “demo” sites impersonate Rockstar and appear in search results for a GTA 6 demo.
  • A Google result advertised an “Official Download,” but the sites deliver a malicious file named `gta6_installer.exe`.
  • The downloaded file is a Vidar infostealer that targets saved passwords, cookies, and authenticated browser sessions.
  • Stolen session cookies can allow account access even if the victim uses 2FA, because the attacker may reuse an already-authenticated session.
  • Known distribution domains include `gta6demo[.]asia`, `gta6demo[.]eu`, `gta6demo[.]us`, and `rockstar-gta-6[.]com`.

Who’s being targeted

  • Commonly targeted roles: All employees, Security awareness program participants, Helpdesk/IT support, Marketing/Comms.
  • Affected industries: Gaming, Media & Entertainment, Consumers/General Public.
  • Attack channels: website.
  • Impersonated: Rockstar Games.

Red flags to watch for

  • A 'demo' is offered even though Rockstar has not announced one
  • The download is a tiny 1.1 MB executable for a supposed AAA game
  • The site uses copied official artwork to look legitimate
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake GTA 6 demo attack work?

Fake sites impersonating Rockstar Games appear in search results for a GTA 6 demo, using Play Now or Official Download buttons that lead victims to download gta6_installer.exe, which is actually a Vidar infostealer.

What data does the malware steal?

The infostealer targets saved passwords, browser cookies, and authenticated browser sessions rather than delivering any actual game content.

Is changing my password enough after this kind of infection?

No, changing a password alone may not be enough because stolen session cookies can let an attacker reuse an already-authenticated session even with 2FA in place. Users should also sign out everywhere and revoke active sessions.

What are the warning signs of this scam?

Red flags include an unannounced demo being offered, a suspiciously tiny 1.1 MB executable claiming to be an AAA game, and use of copied official artwork to appear legitimate.

Read the video transcript

You Google “GTA 6 demo” and see an “Official Download” with Rockstar logos right at the top. Looks legit, right? But that click takes you to gta6demo.asia with a big “Play Now” button. The download is gta6_installer.exe, only 1.1 megabytes. That’s not a demo, it’s Vidar infostealer quietly grabbing your saved passwords and browser cookies. Here’s the nasty part: with those stolen session cookies, someone can open your accounts as if they’re already logged in, even if you use 2FA. Changing your password alone might not kick them out. If you ever downloaded a “GTA 6 demo” or tiny gta6_installer.exe, tell IT now so they can wipe the infostealer and force sign-out on all your accounts.

Similar attacks

Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake GTA 6 “Demo” Sites Push Password-Stealer

Fake GTA 6 “Demo” Sites Push Password-Stealer

Attackers are using convincing Rockstar Games lookalike websites to trick people into downloading a supposed “GTA 6 demo.” The download is actually Vidar infostealer malware that can steal browser passwords, cookies, and logged-in sessions, potentially exposing personal and work accounts if they…

August 27, 2026
Fake GTA 6 Demo Sites Push Password-Stealing Malware

Fake GTA 6 Demo Sites Push Password-Stealing Malware

The article describes real-world scams riding on the GTA 6 leak hype, including fake “Extended Look” and “demo” websites that deliver password-stealing malware. It also warns about “free early access” offers designed to drain crypto wallets, showing how leaked footage can make these lures more…

August 25, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to trick people into installing credential and crypto-stealing malware, and another uses hundreds of imposter GitHub repositories to lure…

July 17, 2026