Fake Rockstar sites are using hype around GTA 6 leaks and the upcoming Extended Look to push a malicious gta6_installer.exe that installs the Vidar infostealer. The campaign steals saved passwords, session cookies, and browser data from multiple browsers and can bypass the protection of 2FA by reusing stolen authenticated sessions. #GTA6 #RockstarGames #Vidar #Cyberleek
Keypoints
- Cybercriminals set up fake Rockstar Games websites that appear in search results for GTA 6 demo downloads.
- The sites imitate Rockstarâs real August 27 Extended Look announcement and use fake âPlay Nowâ buttons to deliver malware.
- The downloaded file, gta6_installer.exe, is a 1.1 MB executable that is not a game or demo but the Vidar infostealer.
- Vidar targets saved browser passwords, session cookies, browsing history, autofill data, and FTP credentials across 19 browsers and related applications.
- Stolen session cookies can let attackers access accounts without re-entering passwords, which may reduce the effectiveness of 2FA in some cases.
- The campaign emerged shortly after new GTA 6 footage and map material circulated online, with responsibility claimed by Cyberleek.
- Malwarebytes blocks the malicious sites and associated infrastructure, while users are advised to verify official sources and sign out of active sessions if infected.
MITRE Techniques
- [T1583.001] Acquire Infrastructure: Domains â The attackers registered or used domains to host fake Rockstar sites and malware delivery pages (âfake GTA 6 demo websitesâ and distribution sites).
- [T1566] Phishing â The fake sites impersonated Rockstar and used convincing branding to lure users into downloading a malicious installer (âfake Rockstar sitesâ and âOfficial Downloadâ).
- [T1204.001] User Execution: Malicious Link â Victims had to click the deceptive âPlay Nowâ links or search-result ads to reach the malicious download (âfollow the sitesâ âPlay Nowâ linksâ).
- [T1105] Ingress Tool Transfer â The malicious executable was delivered to the victim through the fake download flow (âdownloading gta6_installer.exeâ).
- [T1218.007] System Binary Proxy Execution: Mshta â Not mentioned.
- [T1218.005] System Binary Proxy Execution: Rundll32 â Not mentioned.
- [T1056.001] Keylogging â Not mentioned.
- [T1119] Automated Collection â The stealer automatically searched browser profiles and client directories for stored credentials and data (âit went looking for: Saved passwords and login detailsâŚâ).
- [T1539] Steal Web Session Cookie â The malware collected session cookies and authenticated browser sessions (âSession cookiesâ and âstolen browser sessions can sometimes be reusedâ).
- [T1555.003] Credentials from Web Browsers â The sample targeted saved passwords and login data from browsers (âSaved passwords and login detailsâ).
- [T1005] Data from Local System â The malware gathered locally stored browser history, autofill data, and profile information (âBrowsing and download historyâ and âautofill and other saved browser profile dataâ).
- [T1218] System Binary Proxy Execution â The malware launched legitimate installed browser binaries to access protected browser data (âIt launched the actual Chrome, Edge, and Firefox executables installed on the systemâ).
- [T1102.001] Web Service: Dead Drop Resolver â Vidar used profiles on services like Telegram, Pinterest, and Steam to retrieve updated infrastructure (âdead-drop resolversâ and âprofile URLs for Telegram, Pinterest, and Steam Communityâ).
- [T1071.001] Application Layer Protocol: Web Protocols â The sample communicated over normal web traffic to attacker and legitimate services (âmultipart POST requestsâ and âTLS connectionâ).
- [T1095] Non-Application Layer Protocol â Not mentioned.
- [T1070.004] File Deletion â The malware deleted temporary browser directories after use (âit deleted the temporary browser directories it had createdâ).
Indicators of Compromise
- [Domains ] fake distribution sites impersonating Rockstar â gta6demo[.]asiagta6demo[.]eugta6demo[.]us, rockstar-gta-6[.]com
- [File hash (SHA-256) ] malicious installer sample â a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0
- [File name ] delivered payload â gta6_installer.exe
- [Dead-drop resolver URLs ] attacker-controlled profile sources â telegram[.]me/m1duus, pinterest[.]com/m1duus, steamcommunity[.]com/profiles/76561198657426610, and m1duusp[.]me
- [Network infrastructure ] observed command and data endpoints â ses.1001gacor[.]org, ket.sm188daftar[.]mom
- [Additional infrastructure domains ] related Vidar nodes â ket.1001gacor[.]org, ljr.1001gacor[.]org, nhg.1001gacor[.]org, and 14 more items