Fake GTA 6 Demo Sites Push Password-Stealing Malware

Malwarebytes · Medium sophistication
Last updated August 25, 2026

The article describes real-world scams riding on the GTA 6 leak hype, including fake “Extended Look” and “demo” websites that deliver password-stealing malware. It also warns about “free early access” offers designed to drain crypto wallets, showing how leaked footage can make these lures more believable.

Key findings

  • Malwarebytes reports fake “GTA 6 Extended Look” and “demo” sites that deliver an infostealer (password-stealing malware).
  • Scammers are using “free early access” promises to trick people into handing over crypto wallet value.
  • Real leaked footage can make scam pages feel more credible to victims.
  • A separate (non-social-engineering) section describes ShinyHunters stealing Rockstar records by targeting a third party (Anodot) holding persistent authentication tokens.

Who’s being targeted

  • Commonly targeted roles: All employees, Security awareness training audience, Employees who use Discord/online communities, Employees who use cryptocurrency wallets.
  • Affected industries: Gaming, Consumer/Entertainment, Information/Media.
  • Attack channels: website.
  • Impersonated: Rockstar / GTA 6 (implied by the fake demo/look branding), GTA 6 / Rockstar (implied by the early access offer).

Awareness takeaways

  • Do not trust ‘early access’ promises or unofficial demos, use only official purchase/download channels.
  • Treat hype events (leaks, viral clips) as a risk signal, attackers use them to make scams feel authentic.
  • If a page or download claims to be a ‘demo’/‘extended look,’ assume it could be password-stealing malware unless validated.

Red flags to watch for

  • Unsolicited or hype-driven “demo” download for a game that is not officially released
  • Non-official download source (not the official Rockstar store)
  • Pressure/FOMO created by “leaked footage” buzz
  • “Free early access” claims for a highly anticipated title
  • Anything requesting wallet connection or crypto-related steps to ‘unlock’ access
  • Not using official purchase channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You see a link: “GTA 6 Extended Look – playable demo, leaked today.” Tempting, right? Malwarebytes actually found fake GTA 6 “Extended Look” and “demo” sites that install password-stealing malware. Real leaked footage is embedded to make the page feel legit. Another twist: “Free early access to GTA 6, connect your crypto wallet to unlock.” That’s not a bonus, that’s a drain-your-wallet scam. If you see a GTA 6 “demo,” “extended look,” or “free early access” outside official Rockstar channels, assume it’s malware or a wallet scam, close the tab and walk away.

Similar attacks

Fake GTA 6 Demo Sites Push Password Stealer

Fake GTA 6 Demo Sites Push Password Stealer

Attackers are exploiting GTA 6 hype by creating convincing fake Rockstar-branded “demo” websites that appear in Google search results. The sites use “Play Now”/“Official Download” lures to trick people into downloading a small Windows executable that installs Vidar infostealer and steals saved…

August 24, 2026
Fake Microsoft Scan Pushes AV Uninstall Scam

Fake Microsoft Scan Pushes AV Uninstall Scam

Scammers are running Microsoft-branded “SysScan” websites that display a fake security scan and falsely claim Windows no longer supports third‑party antivirus. Victims are pressured to uninstall their antivirus, submit personal and banking details, and prepare for a “refund manager” phone call,…

August 24, 2026
Fake GitHub Lure Tricks macOS Users Into Stealer

Fake GitHub Lure Tricks macOS Users Into Stealer

Researchers described AmnesiaStealer, a macOS info-stealer spread through a counterfeit “Download for macOS” page that tricks users into pasting a command into Terminal. The malware steals passwords and browser session data, and can even give an attacker live, hidden control of the victim’s browser…

August 17, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
npm Mirrors Used for Fake Cloudflare CAPTCHA Phish

npm Mirrors Used for Fake Cloudflare CAPTCHA Phish

Researchers found a real phishing campaign abusing npm packages and unpkg mirrors to host a convincing fake Cloudflare CAPTCHA page on a trusted domain. Victims who click the mirrored link are redirected to attacker-controlled infrastructure that could deliver ClickFix-style prompts or credential…

August 25, 2026
Encrypted Prompt Injection Tricks AI Tools

Encrypted Prompt Injection Tricks AI Tools

Researchers demonstrated a prompt-injection method that hides malicious instructions inside encrypted text, then tricks an AI assistant into decrypting it using built-in code tools. In tests, a normal “summarize this page” request could cause Grok to exfiltrate chat data without any click or…

August 25, 2026