VYPR
researchPublished Aug 24, 2026· 1 source

Fake GTA 6 Demo Sites Distribute Vidar Infostealer

Cybercriminals are capitalizing on the immense hype surrounding Grand Theft Auto VI by creating fake demo websites that lure unsuspecting users into downloading the Vidar infostealer.

The anticipation for Grand Theft Auto VI (GTA 6) has reached a fever pitch, with official extended looks scheduled and leaks already circulating online. This intense interest has created a fertile ground for cybercriminals, who are now exploiting the hype with sophisticated phishing campaigns. These campaigns involve fake websites impersonating Rockstar Games, the developer of GTA 6, and are designed to trick users into downloading malicious software disguised as game installers or demo versions.

Malwarebytes Labs has identified a network of these deceptive sites that appear prominently in search results for "GTA 6 demo." These sites meticulously mimic Rockstar's official promotional materials, including the announcement for the upcoming "Extended Look" trailer. However, instead of providing access to game content, they feature "Play Now" buttons that, when clicked, initiate the download of a malicious executable file, often named gta6_installer.exe.

Crucially, there is no legitimate GTA 6 demo available. The game is slated for release on November 19, 2026, for PlayStation 5 and Xbox Series X|S, with no PC version announced yet. The fake sites leverage this information gap, presenting a convincing facade that preys on the desire for early access or leaked content. The small file size of the purported installer—just 1.1 MB—should serve as an immediate red flag, as it is vastly insufficient for a modern AAA game.

The malicious payload delivered by these fake installers is the Vidar infostealer, a well-established malware-as-a-service (MaaS) known for its ability to steal sensitive information from infected systems. Vidar is designed to exfiltrate saved passwords, session cookies, browsing history, and autofill data from a wide range of browsers, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also targets credentials stored in email clients like Thunderbird and even browsers embedded within applications like Roblox Studio.

One of the most concerning capabilities of the Vidar infostealer is its ability to steal session cookies. These cookies allow users to remain logged into websites without repeatedly entering their credentials. By stealing these tokens, attackers can hijack active user sessions, potentially bypassing multi-factor authentication (MFA) and gaining unauthorized access to accounts, including email, social media, gaming, and shopping platforms.

The emergence of these fake demo sites closely follows the leak of GTA 6 gameplay footage and map details, which began circulating online around August 18, 2026. Threat actors often capitalize on such events, using genuine leaks as a smokescreen to distribute their own malicious wares. The timing suggests a coordinated effort to leverage the public's intense curiosity and demand for any GTA 6-related content.

While the Vidar infostealer itself does not typically employ persistence mechanisms to survive a system reboot, the damage is done once sensitive data is exfiltrated. Attackers can continue to use stolen credentials and session tokens long after the malware has been removed from the victim's machine. The malware operates stealthily, often without any visible user-facing windows or noticeable installations, making infections difficult to detect.

Malwarebytes detects the Vidar samples associated with this campaign and is actively blocking the associated websites and infrastructure. Users are strongly advised to exercise extreme caution when searching for game-related content online, to verify the legitimacy of download sources, and to rely on official channels for game information and releases. The allure of a GTA 6 demo is powerful, but the risk of falling victim to credential theft and account compromise is a far greater threat.

Synthesized by Vypr AI