Fake GTA 6 Extended Look and demo sites deliver an infostealer

Fake GTA 6 Extended Look and demo sites deliver an infostealer
Fake Rockstar sites are using hype around GTA 6 leaks and the upcoming Extended Look to push a malicious gta6_installer.exe that installs the Vidar infostealer. The campaign steals saved passwords, session cookies, and browser data from multiple browsers and can bypass the protection of 2FA by reusing stolen authenticated sessions. #GTA6 #RockstarGames #Vidar #Cyberleek

Keypoints

  • Cybercriminals set up fake Rockstar Games websites that appear in search results for GTA 6 demo downloads.
  • The sites imitate Rockstar’s real August 27 Extended Look announcement and use fake “Play Now” buttons to deliver malware.
  • The downloaded file, gta6_installer.exe, is a 1.1 MB executable that is not a game or demo but the Vidar infostealer.
  • Vidar targets saved browser passwords, session cookies, browsing history, autofill data, and FTP credentials across 19 browsers and related applications.
  • Stolen session cookies can let attackers access accounts without re-entering passwords, which may reduce the effectiveness of 2FA in some cases.
  • The campaign emerged shortly after new GTA 6 footage and map material circulated online, with responsibility claimed by Cyberleek.
  • Malwarebytes blocks the malicious sites and associated infrastructure, while users are advised to verify official sources and sign out of active sessions if infected.

MITRE Techniques

  • [T1583.001] Acquire Infrastructure: Domains – The attackers registered or used domains to host fake Rockstar sites and malware delivery pages (‘fake GTA 6 demo websites’ and distribution sites).
  • [T1566] Phishing – The fake sites impersonated Rockstar and used convincing branding to lure users into downloading a malicious installer (‘fake Rockstar sites’ and ‘Official Download’).
  • [T1204.001] User Execution: Malicious Link – Victims had to click the deceptive “Play Now” links or search-result ads to reach the malicious download (‘follow the sites’ “Play Now” links’).
  • [T1105] Ingress Tool Transfer – The malicious executable was delivered to the victim through the fake download flow (‘downloading gta6_installer.exe’).
  • [T1218.007] System Binary Proxy Execution: Mshta – Not mentioned.
  • [T1218.005] System Binary Proxy Execution: Rundll32 – Not mentioned.
  • [T1056.001] Keylogging – Not mentioned.
  • [T1119] Automated Collection – The stealer automatically searched browser profiles and client directories for stored credentials and data (‘it went looking for: Saved passwords and login details…’).
  • [T1539] Steal Web Session Cookie – The malware collected session cookies and authenticated browser sessions (‘Session cookies’ and ‘stolen browser sessions can sometimes be reused’).
  • [T1555.003] Credentials from Web Browsers – The sample targeted saved passwords and login data from browsers (‘Saved passwords and login details’).
  • [T1005] Data from Local System – The malware gathered locally stored browser history, autofill data, and profile information (‘Browsing and download history’ and ‘autofill and other saved browser profile data’).
  • [T1218] System Binary Proxy Execution – The malware launched legitimate installed browser binaries to access protected browser data (‘It launched the actual Chrome, Edge, and Firefox executables installed on the system’).
  • [T1102.001] Web Service: Dead Drop Resolver – Vidar used profiles on services like Telegram, Pinterest, and Steam to retrieve updated infrastructure (‘dead-drop resolvers’ and ‘profile URLs for Telegram, Pinterest, and Steam Community’).
  • [T1071.001] Application Layer Protocol: Web Protocols – The sample communicated over normal web traffic to attacker and legitimate services (‘multipart POST requests’ and ‘TLS connection’).
  • [T1095] Non-Application Layer Protocol – Not mentioned.
  • [T1070.004] File Deletion – The malware deleted temporary browser directories after use (‘it deleted the temporary browser directories it had created’).

Indicators of Compromise

  • [Domains ] fake distribution sites impersonating Rockstar – gta6demo[.]asiagta6demo[.]eugta6demo[.]us, rockstar-gta-6[.]com
  • [File hash (SHA-256) ] malicious installer sample – a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0
  • [File name ] delivered payload – gta6_installer.exe
  • [Dead-drop resolver URLs ] attacker-controlled profile sources – telegram[.]me/m1duus, pinterest[.]com/m1duus, steamcommunity[.]com/profiles/76561198657426610, and m1duusp[.]me
  • [Network infrastructure ] observed command and data endpoints – ses.1001gacor[.]org, ket.sm188daftar[.]mom
  • [Additional infrastructure domains ] related Vidar nodes – ket.1001gacor[.]org, ljr.1001gacor[.]org, nhg.1001gacor[.]org, and 14 more items


Read more: https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer