LIVE · cybersecurity feed
Live wire
Fake GTA 6 Extended Look and demo sites deliver an infostealerCVE-2026-63520 · Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)CISA’s logging guidance works beyond governmentCISA orders urgent patching of actively exploited Zimbra flawZero-Click Grok Chat History Theft: Adversa AI Demonstrates Cryptographic Context InjectionMalware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply ChainHow an Emerging Industrial Protocol Family Could Put OT at Risk
gta 6high

Fake GTA 6 Extended Look and demo sites deliver an infostealer

Cybercriminals are exploiting the hype surrounding the upcoming Grand Theft Auto VI release by distributing fake demo websites that deliver an information-stealing malware. These sites impersonate Rockstar Games and trick users into downloading a malicious executable disguised as a game installer. The malware, identified as belonging to the Vidar family, is designed to steal passwords, session cookies, and other sensitive data from browsers and applications, potentially bypassing two-factor authentication through the reuse of stolen session tokens.

zeroday.news ·

Cybercriminals are exploiting the widespread anticipation for Grand Theft Auto VI by distributing password-stealing malware through fake websites impersonating Rockstar Games. These sites, which appear in search results for a "GTA 6 demo" or "Official Download," lure visitors into downloading a malicious executable disguised as a game installer.

The scam leverages genuine news surrounding the game, including Rockstar's official announcement of an "Extended Look" at GTA 6 premiering on Netflix on August 27. The fraudulent sites meticulously copy Rockstar's promotional material for this event but add deceptive "Play Now" buttons that lead to the malware.

Rockstar Games has not released or announced any demo for Grand Theft Auto VI. The game is slated for release on November 19, 2026, for PlayStation 5 and Xbox Series X|S, with no PC version currently announced. The executable delivered by these fake sites, named `gta6_installer.exe`, is a mere 1.1 MB, a size far too small to contain a modern AAA game, which should immediately raise suspicion.

The malicious file is identified as a Vidar infostealer, a well-known malware family sold as a service to cybercriminals. This particular sample was first detected on August 19, just one day after new, apparently genuine GTA 6 gameplay footage and a map of the game's setting, Leonida, began circulating online. This leak, claimed by a group called Cyberleek, created a fertile environment for scammers by generating high demand for unofficial content.

The Vidar infostealer is designed to exfiltrate sensitive information stored in web browsers. Its targets include saved passwords and login details, session cookies, browsing and download history, autofill data, and other saved browser profile information. Analysis of the malware sample revealed it specifically sought data from 19 different browsers, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also targeted Thunderbird profile directories, Perplexity's Comet browser, and the WebView2 browser embedded within Roblox Studio.

The malware does not establish persistence on the infected system, meaning it does not create startup entries, scheduled tasks, or services to relaunch itself after a reboot. From a victim's perspective, running the supposed installer might appear to do nothing, as it produces no visible user-facing window and installs no noticeable components. However, the damage is done once credentials and session tokens are stolen.

A significant risk posed by this infostealer is its ability to steal session cookies. These tokens allow attackers to reuse authenticated sessions without needing to re-enter passwords or even bypass two-factor authentication (2FA). While 2FA protects the initial login process, a stolen session token is created after a successful login, potentially allowing an attacker to continue using the service without further authentication. Therefore, simply changing passwords after an infection may not be sufficient; users should also sign out of all active sessions or revoke unfamiliar devices through the respective service's security settings.

This incident is not the first time GTA 6 has been targeted by cybercriminals or affected by leaks. In 2022, Rockstar confirmed that development footage of the game had been stolen and published by an attacker. The current wave of scams highlights how major news events and genuine leaks create an environment ripe for exploitation by malware operators, who can easily mimic official branding and leverage public excitement.

gta 6infostealermalwarevidarcybercrime
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

A ReliaQuest employee fell victim to a phishing attack and the hackers gained access to a dashboard. The post ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited appeared first on SecurityWeek.

iran

Iran-linked cyberattack shut down a UK power plant

A suspected Iran-linked cyberattack recently disrupted a small-scale UK power plant, causing it to shut down for four days. While the government confirmed the incident, it emphasized that the wider energy system remained unaffected and highly resilient. This event follows a series of similar cyber intrusions targeting water utilities in the United States, which cybersecurity analysts also suspect are linked to Iran.

cloud

NIST Warns of Unique Security Risks in Multi-Cloud Environments

NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find solutions

breach

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

Cybersecurity company ReliaQuest has confirmed that one of its employees was targeted in a social engineering attack after hackers impersonated a member of the security team. [...]

ransomware

Tricky 'SynkLoader' Multitool May Herald Ransomware

An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features.

security

Your data doesn’t die when you do (Lock and Code S07E17)

This week on the Lock and Code podcast, we speak with Tamara Kneese about the many ways your data remains long after your die.