Fake GTA 6 Demo Alert: One Click Could Steal Your Passwords

FAKE GTAVI
FAKE GTAVI

Cybercriminals are always looking for new ways to exploit popular trends. This time, they are taking advantage of the huge excitement around GTA 6 by creating fake demo websites developed to spread password-stealing malware.

Security researchers at Malwarebytes have discovered an active malware campaign targeting fans eagerly waiting for Grand Theft Auto VI (GTA 6).

The fake websites that look like official Rockstar Games pages, and designed to trick users to download a playable GTA 6 demo or an “Extended Look” version of the game.

The fake websites are being promoted through search engine manipulation (SEO poisoning) and malicious search ads, helping them appear when people search for GTA 6-related content.

However, there is no real demo. Instead, users who download the fake installer unknowingly install Vidar, a dangerous information-stealing malware Vidar can steal sensitive information, including saved passwords and other personal data, putting victims’ online accounts and privacy at risk.

The campaign highlights how cybercriminals are using the enormous hype around GTA 6 to make their scams appear legitimate and convince eager fans to download malicious software.

Exploiting the Hype Cycle

The threat campaign coincides with heightened fan interest following recent leaks and Rockstar’s official promotion for an upcoming gameplay reveal scheduled for late August.

  • The Bait: Scammers created convincing clones of Rockstar’s official media pages. Search result entries for “GTA 6 demo download” or “GTA VI playable build” direct users to these sites, featuring prominent “Play Now” and “Official Download” buttons.
  • The Red Flag: Clicking the link delivers a file named `gta6_installer.exe`. The payload weighs in at just 1.1 MB—an obvious red flag given that a modern AAA game typically requires tens to hundreds of gigabytes.
  • No Official PC Demo Exists: Rockstar Games has not announced or released any playable public demo, beta, or early-access build for Grand Theft Auto VI.

How the Vidar Infostealer Operates

Once executed, the 1.1 MB payload does not open a game setup window or trigger standard software installation prompts. Instead, it quietly runs in the background to harvest sensitive user credentials.

How Vidar operates
How Vidar operates

1. Headless Browser Exploitation: To bypass browser encryption defenses, the Vidar sample launches installed instances of major web browsers (including Chrome, Edge, Firefox, Brave, and Opera) in hidden, “headless” mode. It forces the browsers to decrypt and expose local user profiles from within trusted processes.
2. Credential Theft: The malware extracts saved account passwords, autofill data, browsing history, and credentials stored by local FTP clients across up to 19 different browser targets.
3. Session Hijacking (2FA Bypass): Critically, Vidar harvests active session cookies. Stolen authenticated tokens allow attackers to hijack live web sessions, allowing them to take over email, gaming, social media, and banking accounts without needing to solve multi-factor authentication (MFA) prompts.
4. Dead-Drop Resolvers: The malware connects to public profiles on platforms such as Telegram, Pinterest, and Steam Community to dynamically fetch updated Command-and-Control (C2) server destinations before exfiltrating data via POST requests.

Indicators of Compromise (IoCs)

Security analysts and system administrators can track and block this campaign using the technical signatures identified by Malwarebytes:

Indicator Type Details / Value
Payload Filename gta6_installer.exe
File Hash (SHA-256) a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0
Malware Family Vidar Infostealer
C2 Infrastructure ses.1001gacor[.]org, ket.1001gacor[.]org

Remediation & Mitigation Guidance

Malwarebytes recommends immediate corrective steps for users who attempted to run the fake installer:

  • Isolate & Scan: Disconnect the machine from local networks and perform a full system scan using updated endpoint protection software to quarantine the threat.
  • Revoke Active Sessions: From a secondary, clean device, log into all critical online accounts (starting with primary email, financial, and gaming platforms) and select “Sign Out of All Devices” or “Log Out Everywhere” to invalidate compromised session tokens.
  • Update Passwords: Change credentials for all accounts whose data was saved in the infected browser environment.
  • Distribution Awareness: Gamers should remember that official PC builds or demos are announced exclusively through verified publisher domains (e.g., `rockstargames.com`) or official storefronts like Steam, Epic Games Store, PlayStation Store, and Xbox.

Join Our Club

Enter your Email address to receive notifications | Join over Million Followers

Previous Article
Cyberattack on US water infrastructure

FBI Investigates Cyberattack on U.S. Water Infrastructure Supplier

Related Posts