Cybercriminals are abusing Grand Theft Auto 6 hype to distribute Vidar infostealer malware through fake Rockstar Games websites.
The sites promote a non-existent GTA 6 demo and use convincing “Play Now” buttons to push a malicious file named gta6_installer.exe.
The campaign appeared shortly after leaked GTA 6 footage and maps began circulating online. Attackers used the increased interest in unofficial game builds, leaked clips, and early-access offers to attract victims searching online.
Rockstar has not released a GTA 6 demo, beta, downloadable PC build, or early-access installer.
The game is scheduled for release on November 19, 2026, for PlayStation 5 and Xbox Series X|S. Its August 27 Extended Look is a video presentation, not a playable download.
The fake websites copy Rockstar artwork and the legitimate Extended Look promotion. However, their download buttons deliver a 1.1 MB executable. That file size alone should raise alarms, as a modern AAA game cannot fit into a file of that size.
Vidar Bypasses Browser Encryption
The downloaded executable is Vidar, a malware-as-a-service information stealer used by cybercriminals to collect valuable data from infected Windows devices.
The sample targeted saved passwords, browser cookies, session tokens, browsing history, download records, autofill data, and credentials stored by FTP clients.
It also searched for profile data across 19 browsers, including Google Chrome, Microsoft Edge, Mozilla Firefox, Brave, Opera, and Vivaldi.
Vidar also examined Thunderbird profiles, Perplexity’s Comet browser, and WebView2 data used within Roblox Studio.
The malware did not show visible windows or create an obvious installation process. It also showed no persistence mechanism, such as a scheduled task, startup entry, or service.
That does not reduce the risk. Infostealers only need a short time to collect data and send it to attackers. Once stolen passwords and browser sessions leave the device, threat actors can attempt to access accounts even after the malware is removed.
Modern browsers encrypt stored passwords and cookies to prevent other programs from simply copying and decrypting browser databases. Vidar bypasses this obstacle by using the victim’s own installed browser processes.
During analysis, the malware launched Chrome, Edge, and Firefox in headless mode. It disabled logging and used temporary user-data directories.
Instead of deploying a fake browser or directly breaking encryption, Vidar used legitimate browser executables that already had permission to access their own protected information.
After collecting data, the malware deleted the temporary browser folders. This method shows that browser encryption remains useful, but cannot protect users who run untrusted executables, malwarebytes said.
Indicators of Compromise
| IOC Type | Indicator | Details |
|---|---|---|
| Distribution domain | gta6demo[.]asia | Fake GTA 6 demo website |
| Distribution domain | gta6demo[.]eu | Fake GTA 6 demo w |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN
