Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malware Disguised as GTA 6 Demo Steals User Data

Malware Disguised as GTA 6 Demo Steals User Data

Posted on August 25, 2026 By CWS

A fraudulent demo of Grand Theft Auto VI is being exploited by cybercriminals to harvest users’ passwords and active browser sessions. The malicious campaign preys on the anticipation for the game’s release, using it as a vehicle to install a data-stealing program on Windows systems.

How the Fake Demo Operates

The deceptive operation begins with websites that convincingly mimic Rockstar Games, appearing in search results for a demo of GTA 6. These sites feature official-looking download buttons that, in reality, offer a harmful executable instead of legitimate game content. Malwarebytes has identified this campaign, revealing that the software involved is the Vidar information stealer.

The scheme gained traction following the online dissemination of unauthorized gameplay footage and a speculative map of the Leonida region. The malware’s reach extends beyond gaming, potentially compromising email, social media, shopping, and financial accounts.

The Wider Impact of the Malware

Even users employing unique passwords and two-factor authentication are at risk, as the malware can remain undetected while criminals utilize the stolen information. The fake demo capitalizes on public interest, leveraging a slick imitation of Rockstar’s promotional materials to deceive users. Notably, the supposed installer file is suspiciously small for a game of this scale, serving as a red flag for potential victims.

The malware, first noticed on August 19, does not provide any visible game window upon execution. Researchers found no automatic restart mechanisms, and the program quietly collects sensitive data, including stored login details and session cookies from browsers like Chrome, Edge, and Firefox.

Protecting Yourself from the Threat

Session cookies, which indicate a completed login, are particularly valuable to attackers because they can bypass the need for re-entering passwords or two-factor authentication. The malware exploits trusted software to access this data without overtly breaching browser encryption.

Users who have executed the malicious installer are advised to scan their systems with reliable security software and change crucial passwords from a secure device. It’s essential to log out of all sessions, remove unrecognized devices, and monitor accounts for unusual activity.

To avoid such threats, it’s recommended to download games only from official sources and to be cautious of search ads, leaked builds, and unexpected downloads. Checking file sizes before execution is another precautionary measure.

Indicators of compromise include several domains and URLs linked to the fake demo sites and the Vidar infrastructure. These have been defanged to prevent accidental activation.

Cyber Security News Tags:browser security, Cybersecurity, data protection, fake demo, gaming malware, gaming security, GTA 6, internet security, Malware, online scams, password theft, phishing scam, Rockstar Games, session cookies, Vidar Stealer

Post navigation

Previous Post: Critical Command Injection Flaws in TP-Link Routers
Next Post: Exploits Targeting miniOrange SAML Vulnerabilities in WordPress

Related Posts

APT36 Attacking BOSS Linux Systems With Weaponized ZIP Files to Steal Sensitive Data APT36 Attacking BOSS Linux Systems With Weaponized ZIP Files to Steal Sensitive Data Cyber Security News
Critical React2Shell Flaw Exploited in Major Cyberattack Critical React2Shell Flaw Exploited in Major Cyberattack Cyber Security News
New Sophisticated Attack Bypasses Content Security Policy Using HTML-Injection Technique New Sophisticated Attack Bypasses Content Security Policy Using HTML-Injection Technique Cyber Security News
AI Skill Security Flaw Exposes 26,000 Agents AI Skill Security Flaw Exposes 26,000 Agents Cyber Security News
Multiple vtenext Vulnerabilities Let Attackers Bypass Authentication and Execute Remote Codes Multiple vtenext Vulnerabilities Let Attackers Bypass Authentication and Execute Remote Codes Cyber Security News
Hackers Registered 13,000+ Unique Domains and Leverages Cloudflare to Launch Clickfix Attacks Hackers Registered 13,000+ Unique Domains and Leverages Cloudflare to Launch Clickfix Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Oracle Server Vulnerability Actively Exploited: CISA Warning
  • Silent Patches Leave Defenders Vulnerable
  • Exploits Targeting miniOrange SAML Vulnerabilities in WordPress
  • Malware Disguised as GTA 6 Demo Steals User Data
  • Critical Command Injection Flaws in TP-Link Routers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Oracle Server Vulnerability Actively Exploited: CISA Warning
  • Silent Patches Leave Defenders Vulnerable
  • Exploits Targeting miniOrange SAML Vulnerabilities in WordPress
  • Malware Disguised as GTA 6 Demo Steals User Data
  • Critical Command Injection Flaws in TP-Link Routers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark