Fake GTA 6 “Demo” Sites Push Password-Stealer

TechRepublic Security · Medium sophistication
Last updated August 27, 2026

Attackers are using convincing Rockstar Games lookalike websites to trick people into downloading a supposed “GTA 6 demo.” The download is actually Vidar infostealer malware that can steal browser passwords, cookies, and logged-in sessions, potentially exposing personal and work accounts if they were used in the same browser.

Key findings

  • There is no legitimate GTA 6 demo; lookalike Rockstar sites are offering a fake download.
  • The fake sites use a “Play Now” button to download a small executable named `gta6_installer.exe`, which was identified as Vidar infostealer.
  • The malware targets browser-stored data including saved passwords, session cookies, autofill data, and browsing history, potentially exposing work, banking, and shopping accounts.
  • Stolen session cookies can allow account access without re-entering credentials or completing MFA again, making session theft especially risky.
  • Recommended response includes scanning the device, changing passwords from a clean device, and signing out active sessions; notify IT/security if work accounts were involved.

Who’s being targeted

  • Commonly targeted roles: All employees, Helpdesk/IT support, Security team, Employees with access to sensitive web-based apps (email, finance, HR, admin consoles).
  • Affected industries: Gaming/Entertainment, Any organization where employees use browsers for work accounts (cross-industry).
  • Attack channels: website.
  • Impersonated: Rockstar Games (lookalike website).

Awareness takeaways

  • Treat “too good to be true” downloads tied to major releases as high risk; verify offers using official channels before clicking.
  • Avoid downloading software from unofficial sites or search ads; use recognized stores and official vendor pages only.
  • Session cookies can bypass normal logins; if malware runs, assume accounts may be compromised even if MFA is enabled.
  • If a personal-looking scam may have touched work accounts, escalate to IT/security and follow incident steps (scan, reset from a clean device, revoke sessions).

Red flags to watch for

  • There is no official GTA 6 demo (offer itself is the warning sign).
  • Download is offered outside Rockstar or a recognized game store.
  • Installer is suspiciously small for a modern game (1.1 MB).
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

See a Rockstar‑looking site shouting “GTA 6 Demo – Play Now”? That demo does not exist. Those “Play Now” buttons download a tiny file called gta6_installer.exe. Malwarebytes found it’s Vidar infostealer, designed to rip browser passwords, cookies, and logged‑in sessions. Here’s the nasty part: if Vidar steals your session cookies, someone can jump straight into your accounts, personal and work, without your password or MFA, because it reuses your already logged‑in browser session. If you ever ran a fake GTA 6 demo, stop using that device, call IT, and from a clean machine change your passwords and sign out of all active sessions.

Similar attacks

Fake GTA 6 Demo Sites Push Password Stealer

Fake GTA 6 Demo Sites Push Password Stealer

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved…

August 24, 2026
Fake GTA 6 Demo Sites Push Password-Stealing Malware

Fake GTA 6 Demo Sites Push Password-Stealing Malware

The article describes real-world scams riding on the GTA 6 leak hype, including fake “Extended Look” and “demo” websites that deliver password-stealing malware. It also warns about “free early access” offers designed to drain crypto wallets, showing how leaked footage can make these lures more…

August 25, 2026
Encrypted Prompt Injection Tricks AI Tools

Encrypted Prompt Injection Tricks AI Tools

Researchers demonstrated a prompt-injection method that hides malicious instructions inside encrypted text, then tricks an AI assistant into decrypting it using built-in code tools. In tests, a normal “summarize this page” request could cause Grok to exfiltrate chat data without any click or…

August 25, 2026
AI Browser Tricked into Spamming WhatsApp, Shopping

AI Browser Tricked into Spamming WhatsApp, Shopping

Researchers showed how a malicious web page could trick OpenAI’s Atlas AI-enabled browser into taking actions a user didn’t intend, like spamming WhatsApp contacts or modifying an Amazon account. The attacks used prompt-injection style instructions hidden in a seemingly legitimate “newsletter…

August 6, 2026
Fake Fortnite Rewards Lure Epic Login Theft

Fake Fortnite Rewards Lure Epic Login Theft

Scammers are setting up fake Fortnite “rewards,” “locker value,” and “competition” websites that funnel players to a fake Epic Games login page. The sites trick people into signing in so attackers can steal Epic usernames and passwords, then take over accounts for resale, fraud, or further scams. A…

July 31, 2026
Fake ChatGPT Billing Emails Steal Card Details

Fake ChatGPT Billing Emails Steal Card Details

Check Point reports that scammers are now impersonating ChatGPT/OpenAI in phishing campaigns, reflecting how mainstream the service has become. One documented example used a fake “ChatGPT Plus payment failure” notice that sent victims to a fraudulent payment page designed to capture full credit…

July 28, 2026