Fake GTA 6 Demo Sites Push Password Stealer

Malwarebytes · Medium sophistication
Last updated August 25, 2026

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved passwords and browser session cookies.

How the attack worked

Attackers built a network of websites impersonating Rockstar Games that surfaced in search results for people looking for a GTA 6 demo. The sites used copied official artwork and a Play Now or Official Download button to appear legitimate. Clicking through led victims to download a file named gta6_installer.exe, which was not a game demo at all but a Vidar infostealer designed to harvest saved browser passwords, cookies, and authenticated sessions.

Why it succeeded

The campaign relied on timing and hype rather than technical sophistication. Rockstar has not announced or released a demo of Grand Theft Auto VI, but the sites exploited public anticipation and search behavior around the topic. Attackers can buy advertisements and optimize malicious pages for exactly the terms people search during major news events, placing fraudulent content directly in front of eager users who are less likely to scrutinize a download before running it.

What to watch for

  • Any download claiming to be an unreleased demo, beta, or early build of a well-known game or product
  • A tiny executable file size for something supposedly containing a full game, such as the 1.1 MB installer used here
  • Search results or ads that promise exclusive or early access tied to trending news
  • Domains with slight variations on the official brand name, similar to the gta6demo and rockstar-gta-6 domains identified in this case

How to build resistance

Organizations and individuals can reduce risk from this type of attack by treating unreleased or unofficial download offers as suspicious by default and verifying claims through the publisher's official channels before downloading anything. Security awareness efforts should reinforce that search results and ads are not inherently trustworthy, especially during high-interest news cycles. If a stealer infection is suspected, resetting passwords alone is not sufficient; affected users should also sign out everywhere, revoke active sessions, and remove unfamiliar devices from their accounts to neutralize any stolen session cookies. This scenario is particularly relevant to general employees who may browse gaming or entertainment content on work or personal devices, as well as marketing and communications staff who monitor trending topics and could encounter these lures while researching public interest around a major release.

Key findings

  • Fake GTA 6 “demo” sites impersonate Rockstar and appear in search results for a GTA 6 demo.
  • A Google result advertised an “Official Download,” but the sites deliver a malicious file named `gta6_installer.exe`.
  • The downloaded file is a Vidar infostealer that targets saved passwords, cookies, and authenticated browser sessions.
  • Stolen session cookies can allow account access even if the victim uses 2FA, because the attacker may reuse an already-authenticated session.
  • Known distribution domains include `gta6demo[.]asia`, `gta6demo[.]eu`, `gta6demo[.]us`, and `rockstar-gta-6[.]com`.

Who’s being targeted

  • Commonly targeted roles: All employees, Security awareness program participants, Helpdesk/IT support, Marketing/Comms.
  • Affected industries: Gaming, Media & Entertainment, Consumers/General Public.
  • Attack channels: website.
  • Impersonated: Rockstar Games.

Red flags to watch for

  • A 'demo' is offered even though Rockstar has not announced one
  • The download is a tiny 1.1 MB executable for a supposed AAA game
  • The site uses copied official artwork to look legitimate
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How does the fake GTA 6 demo attack work?

Fake sites impersonating Rockstar Games appear in search results for a GTA 6 demo, using Play Now or Official Download buttons that lead victims to download gta6_installer.exe, which is actually a Vidar infostealer.

What data does the malware steal?

The infostealer targets saved passwords, browser cookies, and authenticated browser sessions rather than delivering any actual game content.

Is changing my password enough after this kind of infection?

No, changing a password alone may not be enough because stolen session cookies can let an attacker reuse an already-authenticated session even with 2FA in place. Users should also sign out everywhere and revoke active sessions.

What are the warning signs of this scam?

Red flags include an unannounced demo being offered, a suspiciously tiny 1.1 MB executable claiming to be an AAA game, and use of copied official artwork to appear legitimate.

Read the video transcript

You Google “GTA 6 demo” and see an “Official Download” with Rockstar logos right at the top. Looks legit, right? But that click takes you to gta6demo.asia with a big “Play Now” button. The download is gta6_installer.exe, only 1.1 megabytes. That’s not a demo, it’s Vidar infostealer quietly grabbing your saved passwords and browser cookies. Here’s the nasty part: with those stolen session cookies, someone can open your accounts as if they’re already logged in, even if you use 2FA. Changing your password alone might not kick them out. If you ever downloaded a “GTA 6 demo” or tiny gta6_installer.exe, tell IT now so they can wipe the infostealer and force sign-out on all your accounts.

Similar attacks

Fake LastPass GitHub Drops Rapuncel Stealer

Fake LastPass GitHub Drops Rapuncel Stealer

Attackers impersonated LastPass on GitHub and tricked people searching for the “LastPass Authenticator download” into installing a fake installer. The infection chain used a Microsoft-signed driver to disable many security tools, then deployed an infostealer that stole passwords, crypto wallets,…

September 23, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
Fake Downloads and Extensions Steal Sessions Fast

Fake Downloads and Extensions Steal Sessions Fast

The article highlights real, ongoing campaigns where attackers trick people into installing malware via fake software-download websites and a disguised browser extension. These lures are used to steal credentials, browser cookies, and authenticated sessions, letting attackers take over accounts…

September 11, 2026
Custom GPT ‘ClickFix’ Lured Users to Run Malware

Custom GPT ‘ClickFix’ Lured Users to Run Malware

This weekly bulletin highlights multiple real-world incidents, including phishing and impersonation campaigns. Notably, researchers found attackers using malicious “Custom GPTs” on ChatGPT to redirect victims to a Google Sites page and trick them into running commands that install remote-access…

October 5, 2026
Fake IT Helpdesk Tricks Users Into Remote Access

Fake IT Helpdesk Tricks Users Into Remote Access

This bulletin describes multiple real-world social engineering campaigns where attackers impersonate IT support or use trusted-looking sharing and “Allow” prompts to gain access. Several campaigns abuse Microsoft Teams and document-sharing lures to trick employees into installing remote tools or…

September 3, 2026
Fake GTA 6 “Demo” Sites Push Password-Stealer

Fake GTA 6 “Demo” Sites Push Password-Stealer

Attackers are using convincing Rockstar Games lookalike websites to trick people into downloading a supposed “GTA 6 demo.” The download is actually Vidar infostealer malware that can steal browser passwords, cookies, and logged-in sessions, potentially exposing personal and work accounts if they…

August 27, 2026