Fake GTA 6 Demo Spreads Malware: How to Spot the Scam

Fake GTA 6 Demo Spreads Malware: How to Spot the Scam

A fake GTA 6 demo is spreading Vidar malware designed to steal passwords, cookies, and browser sessions. Image: Generated by ChatGPT.

There is no legitimate GTA 6 demo. Fake Rockstar sites are distributing Vidar malware that targets passwords, cookies, and logged-in browser sessions.

Aug 26, 2026
We may earn from vendors via affiliate links or sponsorships. This might affect product placement on our site, but not the content of our reviews. See our Terms of Use for details.

A fake GTA 6 demo circulating through convincing Rockstar Games lookalike sites is actually password-stealing malware. No legitimate Grand Theft Auto VI demo is available to download, and Rockstar has not announced a PC version.

The scam matters beyond gaming accounts because the malware targets information stored in web browsers, including passwords, cookies, and authenticated sessions. If the affected browser is also used for email, work apps, banking, or shopping, those accounts may be exposed too.

How the fake GTA 6 demo scam works

Malwarebytes identified a network of sites impersonating Rockstar Games and promoting a supposed GTA 6 demo. Their “Play Now” buttons can download a file called gta6_installer.exe.

The executable is only 1.1 MB, far too small to contain a modern AAA game. Malwarebytes identified it as Vidar, an information stealer sold to cybercriminals.

The sites are more convincing because they copy genuine GTA 6 artwork and information about Rockstar’s August 27 Extended Look. Similar fake downloads have used anticipated movies and other entertainment releases to hide password-stealing malware.

What the malware can steal

Malwarebytes found the Vidar sample targeting saved passwords, session cookies, browsing history, autofill data, and FTP credentials.

It searched 19 browsers, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also targeted Thunderbird profiles, Perplexity’s Comet browser, and WebView2 inside Roblox Studio.

Stolen cookies are particularly important because attackers may be able to reuse an already authenticated browser session without completing the normal login process again. That means two-factor authentication alone does not necessarily protect an account after a session token is stolen.

The campaign also demonstrates why browser-stored credentials remain attractive targets for infostealers.

Advertisement

How to spot the scam and respond

The simplest warning sign is also the strongest: there is no official GTA 6 demo. Any site offering one is fake, regardless of how convincing its Rockstar branding looks.

Other red flags include:

  • A game download offered outside Rockstar or a recognized game store.
  • Search ads or unofficial sites claiming an “official” demo.
  • A suspiciously tiny installer.
  • Pressure to download leaked, beta, or early-access material.

If you downloaded the file but did not run it, delete it and scan the device.

If you ran it, Malwarebytes recommends assuming browser credentials and active sessions may have been compromised. Scan the computer, then use a clean device to change important passwords and sign out of active sessions. Check accounts for unfamiliar devices, recovery details, forwarding rules, or connected applications.

If work accounts were open in the affected browser, notify your IT or security team rather than treating the incident as only a personal gaming scam.

Also read: Our Windows 11 security cheat sheet explains built-in protections including Defender, BitLocker, passkeys, and other Windows security features.