Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Anthropic Enhances Claude Security with Enterprise-Managed Authentication
August 25, 2026
Minecraft Malware: Top Google Results Led Gamers to Dangerous Downloads
August 25, 2026
Fake GTA 6 Demo Delivers ‘Stealer’ Malware, Steals Passwords and Sessions
August 25, 2026
Home/Threats/Fake GTA 6 Demo Delivers ‘Stealer’ Malware, Steals Passwords and Sessions
Threats

Fake GTA 6 Demo Delivers ‘Stealer’ Malware, Steals Passwords and Sessions

Key Takeaways A malicious campaign is distributing a fake Grand Theft Auto VI demo to deploy the Vidar information stealer. The malware targets Windows users seeking early access to the highly...

David kimber
David kimber
August 25, 2026 4 Min Read
2 0

Key Takeaways

  • A malicious campaign is distributing a fake Grand Theft Auto VI demo to deploy the Vidar information stealer.
  • The malware targets Windows users seeking early access to the highly anticipated game.
  • Attackers use convincing fake websites mimicking Rockstar Games to lure victims.
  • Successful infection leads to the theft of passwords, session cookies, browsing history, and credentials from various applications.
  • Even users with unique passwords and two-factor authentication are at risk due to session cookie theft.

Cybersecurity researchers have uncovered a new threat targeting enthusiasts eager for early access to Grand Theft Auto VI. A deceptive campaign is leveraging the immense anticipation surrounding the game to distribute the Vidar information stealer, compromising user credentials and active browser sessions on Windows systems.

Table Of Content

  • Key Takeaways
  • Fake GTA 6 Demo Is Actually Malware
  • Stolen Sessions Raise Account Risks
  • What You Should Do

The operation capitalizes on the widespread excitement generated by leaked game footage and upcoming official announcements. Threat actors have created sophisticated phishing websites that closely resemble official Rockstar Games properties. These sites appear prominently in search results for “GTA 6 demo” and feature enticing “Download” or “Play Now” buttons, which, when clicked, unleash a malicious executable instead of legitimate game content or a playable demo.

Malwarebytes identified the campaign and said in a report shared with Cyber Security News (CSN) that the delivered file is a variant of the notorious Vidar information stealer. This activity surged as public interest intensified following the unauthorized circulation of gameplay clips and an alleged map of the fictional state of Leonida, highlighting how attackers exploit trending topics for their malicious endeavors.

The ramifications of such an infection extend far beyond a single gaming account. A successful compromise can expose a victim’s email, social media, shopping, payment, and other gaming accounts. Critically, stolen session data can enable attackers to bypass authentication mechanisms entirely, gaining unauthorized access to accounts where users are already logged in.

This makes the fake demo a significant risk, even for individuals who diligently use unique passwords and two-factor authentication (2FA). The stealthy nature of the infection means it can remain undetected until attackers begin exploiting the stolen data, making prompt detection and response crucial.

Fake GTA 6 Demo Is Actually Malware

It is important to emphasize that no official GTA 6 demo, beta, PC build, or any downloadable early version currently exists. The genuine “extended look” from Rockstar Games is a video presentation. Scammers have meticulously mimicked official promotional artwork and language to lend credibility to their fraudulent pages.

A key indicator of the malicious nature of the download is its size: the supposed installer is merely 1.1 MB. This is an immediate red flag for any modern, high-fidelity game release, which typically requires gigabytes of data. The timing of this malicious activity is also strategic; the first malicious sample was observed on August 19, just one day after the most recent leaks began to spread widely. This demonstrates the attackers’ agility in capitalizing on breaking news and public demand.

The high volume of search interest for a GTA 6 demo provided a fertile ground for criminals, mirroring past instances where fake game downloads have exploited popular entertainment brands to conceal credential-stealing malware.

Upon execution, the malicious program does not display any visible game window or install recognizable software. Researchers found no persistent mechanisms, such as startup entries, scheduled tasks, or services, indicating that the malware is designed for a quick data exfiltration and then to disappear, leaving minimal traces.

Instead, the Vidar stealer silently harvests sensitive information, including saved login credentials, browser session cookies, browsing history, download records, autofill data, and credentials from FTP clients. The malware specifically targets data from 19 different browser types, including popular options like Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also seeks data from Thunderbird email clients and the browser component within Roblox Studio. Vidar has a history of being employed in gaming-related lures, as evidenced by a Vidar cheat campaign earlier this year.

Stolen Sessions Raise Account Risks

Beyond passwords, browser-stored session cookies represent a significant vulnerability. These small data packets confirm a user’s prior login to a website. If stolen and still valid, an attacker can reuse these cookies to bypass the login process entirely, circumventing both password entry and multi-factor authentication checks.

This capability means that simply changing passwords might not be enough to secure compromised accounts. The Vidar malware operates by launching legitimate Chrome, Edge, and Firefox processes in a hidden mode to access protected browser data. It then deletes temporary folders to cover its tracks. This method exploits the trusted nature of browser applications to access their own data, rather than attempting to directly break browser encryption, making it more difficult to detect. The malware also communicated with Telegram, Pinterest, and Steam Community profiles, which are often used as dynamic “dead-drop resolvers” to point to attacker-controlled servers.

Observed connections were made to two malicious destinations. This pattern of combining seemingly ordinary web traffic with credential theft echoes the risks associated with replaying stolen browser cookies to hijack active sessions.

What You Should Do

  • Immediately scan any affected computer with reputable antivirus or anti-malware software to detect and remove the threat.
  • From a clean, uncompromised device, change all critical passwords, prioritizing email and financial accounts.
  • Log out of all active sessions across all online services.
  • Review connected devices and applications for unfamiliar entries and remove them.
  • Update recovery details (e.g., phone numbers, secondary email addresses) for all accounts.
  • Monitor all your online accounts closely for any suspicious activity.
  • Always obtain games and software exclusively from official publishers or established, legitimate digital storefronts.
  • Exercise extreme caution with search advertisements, unofficial “leaked” builds, or unexpected download prompts.
  • Verify file sizes before executing any downloaded program; legitimate games are typically large.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackMalwareSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Critical TP-Link Archer Flaws Let Attackers Inject Commands

Next Post

Minecraft Malware: Top Google Results Led Gamers to Dangerous Downloads

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft Teams Update Lets Admins Auto-Block Meeting Bots
August 24, 2026
Critical Zimbra RCE Bug Actively Exploited, Patch Now
August 24, 2026
Google, Bing Search Results Poisoned to Deliver Banking Phishing
August 24, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us