Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved passwords and browser session cookies.
How the attack worked
Attackers built a network of websites impersonating Rockstar Games that surfaced in search results for people looking for a GTA 6 demo. The sites used copied official artwork and a Play Now or Official Download button to appear legitimate. Clicking through led victims to download a file named gta6_installer.exe, which was not a game demo at all but a Vidar infostealer designed to harvest saved browser passwords, cookies, and authenticated sessions.
Why it succeeded
The campaign relied on timing and hype rather than technical sophistication. Rockstar has not announced or released a demo of Grand Theft Auto VI, but the sites exploited public anticipation and search behavior around the topic. Attackers can buy advertisements and optimize malicious pages for exactly the terms people search during major news events, placing fraudulent content directly in front of eager users who are less likely to scrutinize a download before running it.
What to watch for
- Any download claiming to be an unreleased demo, beta, or early build of a well-known game or product
- A tiny executable file size for something supposedly containing a full game, such as the 1.1 MB installer used here
- Search results or ads that promise exclusive or early access tied to trending news
- Domains with slight variations on the official brand name, similar to the gta6demo and rockstar-gta-6 domains identified in this case
How to build resistance
Organizations and individuals can reduce risk from this type of attack by treating unreleased or unofficial download offers as suspicious by default and verifying claims through the publisher's official channels before downloading anything. Security awareness efforts should reinforce that search results and ads are not inherently trustworthy, especially during high-interest news cycles. If a stealer infection is suspected, resetting passwords alone is not sufficient; affected users should also sign out everywhere, revoke active sessions, and remove unfamiliar devices from their accounts to neutralize any stolen session cookies. This scenario is particularly relevant to general employees who may browse gaming or entertainment content on work or personal devices, as well as marketing and communications staff who monitor trending topics and could encounter these lures while researching public interest around a major release.
Key findings
- Fake GTA 6 “demo” sites impersonate Rockstar and appear in search results for a GTA 6 demo.
- A Google result advertised an “Official Download,” but the sites deliver a malicious file named `gta6_installer.exe`.
- The downloaded file is a Vidar infostealer that targets saved passwords, cookies, and authenticated browser sessions.
- Stolen session cookies can allow account access even if the victim uses 2FA, because the attacker may reuse an already-authenticated session.
- Known distribution domains include `gta6demo[.]asia`, `gta6demo[.]eu`, `gta6demo[.]us`, and `rockstar-gta-6[.]com`.
Who’s being targeted
- Commonly targeted roles: All employees, Security awareness program participants, Helpdesk/IT support, Marketing/Comms.
- Affected industries: Gaming, Media & Entertainment, Consumers/General Public.
- Attack channels: website.
- Impersonated: Rockstar Games.
Red flags to watch for
- A 'demo' is offered even though Rockstar has not announced one
- The download is a tiny 1.1 MB executable for a supposed AAA game
- The site uses copied official artwork to look legitimate
Frequently asked questions
How does the fake GTA 6 demo attack work?
Fake sites impersonating Rockstar Games appear in search results for a GTA 6 demo, using Play Now or Official Download buttons that lead victims to download gta6_installer.exe, which is actually a Vidar infostealer.
What data does the malware steal?
The infostealer targets saved passwords, browser cookies, and authenticated browser sessions rather than delivering any actual game content.
Is changing my password enough after this kind of infection?
No, changing a password alone may not be enough because stolen session cookies can let an attacker reuse an already-authenticated session even with 2FA in place. Users should also sign out everywhere and revoke active sessions.
What are the warning signs of this scam?
Red flags include an unannounced demo being offered, a suspiciously tiny 1.1 MB executable claiming to be an AAA game, and use of copied official artwork to appear legitimate.
Read the video transcript
You Google “GTA 6 demo” and see an “Official Download” with Rockstar logos right at the top. Looks legit, right? But that click takes you to gta6demo.asia with a big “Play Now” button. The download is gta6_installer.exe, only 1.1 megabytes. That’s not a demo, it’s Vidar infostealer quietly grabbing your saved passwords and browser cookies. Here’s the nasty part: with those stolen session cookies, someone can open your accounts as if they’re already logged in, even if you use 2FA. Changing your password alone might not kick them out. If you ever downloaded a “GTA 6 demo” or tiny gta6_installer.exe, tell IT now so they can wipe the infostealer and force sign-out on all your accounts.