A fraudulent demo of Grand Theft Auto VI is being exploited by cybercriminals to harvest users’ passwords and active browser sessions. The malicious campaign preys on the anticipation for the game’s release, using it as a vehicle to install a data-stealing program on Windows systems.
How the Fake Demo Operates
The deceptive operation begins with websites that convincingly mimic Rockstar Games, appearing in search results for a demo of GTA 6. These sites feature official-looking download buttons that, in reality, offer a harmful executable instead of legitimate game content. Malwarebytes has identified this campaign, revealing that the software involved is the Vidar information stealer.
The scheme gained traction following the online dissemination of unauthorized gameplay footage and a speculative map of the Leonida region. The malware’s reach extends beyond gaming, potentially compromising email, social media, shopping, and financial accounts.
The Wider Impact of the Malware
Even users employing unique passwords and two-factor authentication are at risk, as the malware can remain undetected while criminals utilize the stolen information. The fake demo capitalizes on public interest, leveraging a slick imitation of Rockstar’s promotional materials to deceive users. Notably, the supposed installer file is suspiciously small for a game of this scale, serving as a red flag for potential victims.
The malware, first noticed on August 19, does not provide any visible game window upon execution. Researchers found no automatic restart mechanisms, and the program quietly collects sensitive data, including stored login details and session cookies from browsers like Chrome, Edge, and Firefox.
Protecting Yourself from the Threat
Session cookies, which indicate a completed login, are particularly valuable to attackers because they can bypass the need for re-entering passwords or two-factor authentication. The malware exploits trusted software to access this data without overtly breaching browser encryption.
Users who have executed the malicious installer are advised to scan their systems with reliable security software and change crucial passwords from a secure device. It’s essential to log out of all sessions, remove unrecognized devices, and monitor accounts for unusual activity.
To avoid such threats, it’s recommended to download games only from official sources and to be cautious of search ads, leaked builds, and unexpected downloads. Checking file sizes before execution is another precautionary measure.
Indicators of compromise include several domains and URLs linked to the fake demo sites and the Vidar infrastructure. These have been defanged to prevent accidental activation.
