Cybercriminals are exploiting the widespread anticipation for Grand Theft Auto VI by distributing password-stealing malware through fake websites impersonating Rockstar Games. These sites, which appear in search results for a "GTA 6 demo" or "Official Download," lure visitors into downloading a malicious executable disguised as a game installer.
The scam leverages genuine news surrounding the game, including Rockstar's official announcement of an "Extended Look" at GTA 6 premiering on Netflix on August 27. The fraudulent sites meticulously copy Rockstar's promotional material for this event but add deceptive "Play Now" buttons that lead to the malware.
Rockstar Games has not released or announced any demo for Grand Theft Auto VI. The game is slated for release on November 19, 2026, for PlayStation 5 and Xbox Series X|S, with no PC version currently announced. The executable delivered by these fake sites, named `gta6_installer.exe`, is a mere 1.1 MB, a size far too small to contain a modern AAA game, which should immediately raise suspicion.
The malicious file is identified as a Vidar infostealer, a well-known malware family sold as a service to cybercriminals. This particular sample was first detected on August 19, just one day after new, apparently genuine GTA 6 gameplay footage and a map of the game's setting, Leonida, began circulating online. This leak, claimed by a group called Cyberleek, created a fertile environment for scammers by generating high demand for unofficial content.
The Vidar infostealer is designed to exfiltrate sensitive information stored in web browsers. Its targets include saved passwords and login details, session cookies, browsing and download history, autofill data, and other saved browser profile information. Analysis of the malware sample revealed it specifically sought data from 19 different browsers, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also targeted Thunderbird profile directories, Perplexity's Comet browser, and the WebView2 browser embedded within Roblox Studio.
The malware does not establish persistence on the infected system, meaning it does not create startup entries, scheduled tasks, or services to relaunch itself after a reboot. From a victim's perspective, running the supposed installer might appear to do nothing, as it produces no visible user-facing window and installs no noticeable components. However, the damage is done once credentials and session tokens are stolen.
A significant risk posed by this infostealer is its ability to steal session cookies. These tokens allow attackers to reuse authenticated sessions without needing to re-enter passwords or even bypass two-factor authentication (2FA). While 2FA protects the initial login process, a stolen session token is created after a successful login, potentially allowing an attacker to continue using the service without further authentication. Therefore, simply changing passwords after an infection may not be sufficient; users should also sign out of all active sessions or revoke unfamiliar devices through the respective service's security settings.
This incident is not the first time GTA 6 has been targeted by cybercriminals or affected by leaks. In 2022, Rockstar confirmed that development footage of the game had been stolen and published by an attacker. The current wave of scams highlights how major news events and genuine leaks create an environment ripe for exploitation by malware operators, who can easily mimic official branding and leverage public excitement.






