Grand Theft Auto VI is about crime. Unfortunately, some people have decided the marketing campaign should be interactive.
Security researchers have uncovered a network of fake Rockstar Games websites advertising a playable GTA VI demo that does not exist. Visitors who click the sites' "Play Now" buttons can instead receive a small Windows executable carrying Vidar, a well-known information stealer built to grab passwords, browser cookies, and active login sessions.
The campaign is especially effective because it mixes fake downloads with real GTA VI news. Genuine leaked footage began circulating online in August, and Rockstar has an official extended look at the game scheduled for August 27. Criminals copied that promotion and added one small feature Rockstar did not: a malware button.
There is no official GTA VI demo
Rockstar has not announced a playable demo, beta, early-access PC build, or public test version of GTA VI. The company says the game will launch November 19, 2026 for PlayStation 5 and Xbox Series X|S. No PC release has been announced.
The real August 27 event is an extended look that will premiere on Netflix and later appear on Rockstar's YouTube channel and GTA VI website. It is video, not something you install.
Malwarebytes found fake sites appearing in searches for a GTA VI demo, including pages designed to resemble official Rockstar material. One result advertised an "Official Download." The supposed installer, named gta6_installer.exe, was only about 1.1 MB.
For perspective, a 1.1 MB executable claiming to contain even a meaningful slice of GTA VI is less a red flag than a red stadium floodlight.
The malware is Vidar, and it wants what your browser remembers
Malwarebytes identified the payload as Vidar, an established infostealer sold as a service to cybercriminals. Once run, the sample searches browsers and applications for information that can be turned into account access or sold to other criminals.
The researchers found it targeting 19 browsers, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also searched Thunderbird profile directories, Perplexity's Comet browser, and the WebView2 browser component used inside Roblox Studio.
According to the technical analysis, the sample looks for:
- Saved passwords and login information
- Session cookies
- Browsing and download history
- Autofill and saved browser profile data
- Credentials stored by FTP clients
The sample did not create the usual persistence mechanisms that would relaunch it after a reboot. Researchers saw no startup entry, scheduled task, or Windows service. That does not make it harmless. An infostealer may only need seconds on a machine to send out credentials that remain useful long after the malware itself is gone.
Stolen sessions are why 2FA may not save you
The nastier part of this campaign is session theft. When you log into a website and complete two-factor authentication, the site normally gives your browser a cookie or token proving that authentication already happened. That is what keeps you logged in as you move from page to page.
If malware steals a valid session token, an attacker may be able to reuse the already authenticated session without typing the password or completing a fresh 2FA challenge. Whether that works depends on the service's security controls, but it is a real reason that simply changing a password after an infostealer infection may not be enough.
Malwarebytes also found the sample using a clever route around newer browser protections. It launched legitimate Chrome, Edge, and Firefox binaries in headless mode and pointed them at temporary user-data directories. The goal was to access protected browser information through software already trusted to read it, rather than directly breaking the browser's encryption.
Real leaks helped make the fake download believable
The malware appeared at almost perfect timing for attackers. On August 18, new gameplay footage and what appeared to be a detailed map of Leonida began circulating online under the name Cyberleek. Take-Two responded with takedown efforts and sought records from Microsoft and Discord through DMCA subpoenas.
Malwarebytes first observed the malicious installer on August 19, one day after that leak material began spreading.
That created a messy information environment where real unauthorized footage, recycled clips, AI-generated material, cryptocurrency promotions, and outright malware were all competing for the same searches. Cyberleek material itself included crypto promotion, while its website sought cryptocurrency donations and advertising deals.
For an attacker, that confusion is useful. A fake demo is much easier to sell when people already know that genuine material has escaped Rockstar's control.
If you ran the installer, treat the browser as compromised
Anyone who downloaded one of these supposed demos but did not run the executable is in a much better position. Delete the file and scan the system.
If the executable was run, the safer assumption is that stored credentials and active browser sessions may have been exposed. Security researchers recommend scanning the affected computer, then using a clean device to change important passwords. Start with the primary email account because it is often the recovery route for everything else.
Users should also sign out of all active sessions where services provide that option, remove unfamiliar devices, review recovery email addresses and phone numbers, check for suspicious email forwarding rules, and monitor financial and gaming accounts for unauthorized activity.
The larger lesson is not particularly glamorous, but it works. Search results are not proof that a download is legitimate, copied branding is cheap, and an unreleased blockbuster game is excellent bait. Until Rockstar itself announces a demo, every site promising one deserves exactly the level of trust you would give a stranger in Vice City offering to hold your wallet.
---------------
Author: Alan Ward
Seattle News Desk