- The Mess: Fake GTA 6 demo sites are serving a 1.1 MB
gta6_installer.exethat is actually the Vidar infostealer. Malwarebytes found it targeting passwords, session cookies and browser data across 19 browser profiles. - The Damage: Stolen session cookies can let attackers hijack already-authenticated accounts without needing the victim’s password again.
- The Fix: There is no official GTA 6 demo or PC build — don’t download one, and if you already ran the fake installer, revoke active sessions and change credentials from a clean device.
The GTA 6 hype has officially become an attack surface.
Cybercriminals are now running fake websites pretending to offer a playable Grand Theft Auto VI demo.
There is no such demo.
The download is malware.
And researchers from Malwarebytes have now dissected the sample.
What they found is Vidar, an established information-stealing malware family designed to empty browsers of credentials and session data.
The Download Is Tiny
The supposed installer is only about:
1.1 MB
That’s not a GTA 6 game.
It’s barely enough data to pretend to be one.
The file is named:
gta6_installer.exe
and is presented as a legitimate game installer on websites designed to look like Rockstar-related pages.
The victim clicks.
Windows runs the executable.
And the game never appears.
That’s because there is no game.
Vidar Is the Payload
Malwarebytes identified the sample as belonging to the Vidar infostealer family.
Vidar doesn’t need to encrypt your files.
It doesn’t need to display a ransom note.
It doesn’t need to stay installed for months.
Its job is much simpler:
steal useful information and leave.
And the information sitting inside modern browsers is extremely useful.
It Wants Your Passwords
The sample searched for:
saved passwords
login information
session cookies
browser history
download history
autofill data
and
FTP credentials.
That’s already enough to turn a fake game download into a serious account-security incident.
It Targeted 19 Browsers
This wasn’t some narrowly targeted Chrome-only operation.
Malwarebytes observed the sample targeting 19 browser profiles, including:
Chrome
Edge
Firefox
Brave
Opera
Vivaldi
and others.
It also looked at Thunderbird profiles and even targeted Perplexity’s Comet browser and the WebView2 browser embedded in Roblox Studio.
The attackers clearly weren’t interested only in someone’s Steam password.
They wanted the whole browser environment.
Cookies Are the Really Interesting Part
Passwords are bad.
Session cookies can be worse.
A stolen password can often be neutralized by changing it.
A stolen authenticated session can potentially allow an attacker to act as the already-logged-in user.
That means:
you logged in
↓
browser received session token
↓
Vidar steals token
↓
attacker obtains token
↓
attacker attempts to reuse session
The attacker may not need to know your password at all.
And depending on the service, session theft can complicate MFA protections because the attacker is attempting to reuse an already-authenticated session.
Your Gaming Account Isn’t the Only Target
This is where the story stops being a gaming problem.
Imagine someone downloads the fake GTA 6 demo on a PC they also use for:
Gmail
Microsoft 365
Discord
Steam
PayPal
online shopping
or
work applications.
One malicious executable can potentially expose data from all of them.
The GTA 6 branding is simply the bait.
The Timing Is Perfect
The campaign appeared during a massive wave of GTA 6 attention.
Fresh gameplay material was circulating online.
Rockstar was preparing its official extended reveal.
Fans were desperately searching for new footage and anything resembling an early playable build.
That creates the perfect environment for malware operators.
They don’t have to invent demand.
The Internet already created it for them.
Fake Rockstar Pages Do the Rest
The attackers created websites designed to resemble legitimate GTA-related pages.
The basic psychological trick is simple:
real game
real leaks
real artwork
fake demo
=
victim clicks
The existence of genuine GTA 6 material makes the fake download more believable.
That’s what makes this campaign particularly effective.
There Is No Official GTA 6 Demo
This should be the easiest detection rule of all.
If someone offers:
GTA 6 Demo
GTA 6 PC Beta
GTA 6 Early Access
GTA 6 Playable Build
or
GTA 6 PC Installer
from an unofficial website:
don’t run it.
The file isn’t magically legitimate because the website uses Rockstar artwork.
The Malware Doesn’t Even Need Persistence
Malwarebytes found no startup entry, scheduled task or installed service designed to make the sample survive a reboot.
At first glance, that might sound like good news.
It isn’t necessarily.
An infostealer doesn’t need to live on your computer for weeks.
It needs enough time to steal the valuable material.
Once the attacker has your credentials and session tokens, the malware can disappear.
That Makes Detection Harder
The victim may see:
nothing.
No ransomware screen.
No fake Windows warning.
No obvious browser popup.
No permanent application.
Malwarebytes observed that the sample could run without producing a visible user-facing window.
Someone might simply think:
“The GTA 6 installer didn’t work.”
Then close it.
The actual attack may already be finished.
Vidar Can Use Legitimate Services
The campaign also shows another useful technique.
The sample contained references to attacker-controlled profiles on services including Telegram, Pinterest and Steam Community and used them as part of its infrastructure.
That gives attackers flexibility.
Instead of hard-coding one permanent command-and-control address, infrastructure can be changed more easily.
It’s another reason traditional blocklists don’t solve the entire problem.
Search Engines Are Part of the Attack Surface
The fake GTA 6 sites don’t need to be sent directly to every victim.
They can be discovered through search.
Someone searches:
“GTA 6 demo download”
or
“GTA 6 PC beta”
or
“GTA 6 playable build”
and lands on a convincing fake.
That’s why SEO poisoning is so useful for malware campaigns.
The victim is already looking for the bait.
The 1.1 MB File Is a Red Flag
A supposed full modern AAA game delivered as a 1.1 MB executable should immediately trigger suspicion.
But attackers know that many people don’t think about file size.
They think:
“Maybe it’s just the launcher.”
Then the executable gets a chance to run.
That’s all the attacker needs.
What If You Already Ran It?
Don’t assume that deleting gta6_installer.exe solves the problem.
If the malware executed, assume credentials and session data may have been exposed.
From a clean device:
change important passwords
revoke active sessions
enable MFA
check recent account activity
and
investigate the affected machine.
For high-value accounts, session revocation is particularly important because changing a password alone may not invalidate every previously issued session.
Start With Email
If your browser credentials were stolen, email should be one of the first accounts to secure.
Why?
Because email can be the reset mechanism for almost everything else.
An attacker who obtains your mailbox can potentially reset:
social accounts
gaming accounts
shopping accounts
and
cloud services.
Protect the recovery account first.
Then Check Your Browser Accounts
Look at:
Microsoft
Apple
Steam
Discord
and other accounts where the browser stored credentials or active sessions.
Check:
recent logins
new devices
unknown locations
and
active sessions.
Anything you don’t recognize deserves investigation.
Corporate Machines Are Even More Interesting
The really ugly scenario is someone downloading the fake demo on a machine used for work.
The attacker doesn’t care that the victim was trying to play GTA 6.
If that browser contains:
Microsoft 365 sessions
Google Workspace
GitHub credentials
VPN portals
cloud dashboards
or
internal web applications,
the gaming lure has just become an enterprise intrusion vector.
Gaming Is Now a Security Beat
This is exactly why Bugstoday should track gaming security.
We’re not interested in:
“GTA 6 looks amazing.”
We’re interested in:
“GTA 6 hype is being weaponized to distribute an infostealer.”
That’s a security story.
And a very good one.
The Attack Is Bigger Than GTA
The same technique can be reused tomorrow with:
Call of Duty
Minecraft
Fortnite
Battlefield
Grand Theft Auto
or any other game generating massive search traffic.
The game changes.
The malware doesn’t have to.
Bugstoday Opinion
This is the kind of gaming story we want.
There is no need to turn Bugstoday into another gaming news site.
We simply follow the attack surface.
In this case, gamers are being used as the delivery mechanism for a password and session-token thief.
The irony is almost too clean:
people are downloading a game to escape reality, and instead they’re handing their browser to a criminal.
Bugstoday verdict: the GTA 6 demo isn’t leaked. Your passwords are. The fake installer is Vidar, and its real target isn’t the game — it’s everything you’ve already logged into through your browser. If a random website suddenly offers a “GTA 6 PC demo”, close the tab. There is no legitimate reason to run that executable.




