
Malicious websites impersonating Rockstar Games are exploiting interest in Grand Theft Auto VI leaks and an upcoming official preview to distribute the Vidar information stealer.
The campaign uses fake “Play Now” and “Official Download” prompts that deliver a 1.1 MB executable named gta6_installer.exe.
Malwarebytes identified a network of fraudulent Rockstar-themed sites appearing in searches for a GTA 6 demo. One malicious page surfaced in Google results and copied artwork and information from Rockstar’s genuine promotion for an Extended Look at GTA 6, making the fake download offer appear more credible.

Malwarebytes
Rockstar Games has not announced a GTA 6 demo or PC version. Grand Theft Auto VI is currently scheduled to launch on November 19, 2026, on PlayStation 5 and Xbox Series X|S, while an official Extended Look is due to premiere on Netflix on August 27 before appearing on Rockstar’s YouTube channel. The 1.1 MB file offered by the malicious sites is far too small to contain a modern AAA game.

Malwarebytes
Rockstar Games, a subsidiary of Take-Two Interactive, is the developer behind the Grand Theft Auto and Red Dead Redemption franchises. The company has faced repeated security incidents surrounding GTA 6, including the theft and publication of development footage in 2022 and a new leak that began circulating on August 18, 2026. Rockstar also acknowledged the latest leak in an X post published on August 26.
Malwarebytes said it first observed the malicious executable on August 19, one day after material attributed to a group calling itself Cyberleek began spreading online. The mixture of genuine leaked content, recycled footage, scams, and unofficial downloads created an environment in which fake GTA 6 builds could appear plausible.
Analysis identified the payload as Vidar, an established infostealer sold to cybercriminals as a service. The malware searches for saved passwords, session cookies, browsing and download history, autofill information, and credentials stored by FTP clients.
The sample targeted 19 browsers, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi, as well as Thunderbird profiles, Perplexity’s Comet browser, and the WebView2 component used by Roblox Studio.
Researchers also found that the stealer launched legitimate Chrome, Edge, and Firefox binaries in headless mode and used temporary browser profiles, allowing it to operate through software already permitted to access protected browser data.
The malware contained Telegram, Pinterest, and Steam Community URLs consistent with Vidar’s use of “dead-drop resolvers,” where attacker-controlled profiles provide updated command-and-control information.
Users who ran the fake installer should scan the affected system, change important passwords from a clean device, revoke all active sessions, review accounts for unauthorized changes, and enable two-factor authentication. Revoking sessions is particularly important because stolen cookies can sometimes let attackers bypass the normal password and 2FA login process.







Leave a Reply