Skip to main content

Fake GTA 6 Extended Look and demo sites deliver an infostealer

0
Medium
Published: 08/25/2026 (08/25/2026, 07:10:28 UTC)
Source: AlienVault OTX General

Description

Cybercriminals are exploiting the hype around Grand Theft Auto VI by creating fake websites that impersonate official Rockstar Games promotional material. These sites offer a GTA 6 demo download which is actually a Vidar infostealer malware. The malware steals sensitive browser data including passwords, cookies, session tokens, autofill data, and FTP credentials from multiple browsers. It uses legitimate browser binaries in headless mode to bypass protections and steal data more effectively. Stolen session tokens can bypass two-factor authentication, allowing persistent unauthorized access even after password changes. This campaign leverages recent GTA 6 leaks to lure victims.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 20:04:06 UTC

Technical Analysis

This threat involves fake websites impersonating Rockstar Games to distribute a malicious executable named gta6_installer.exe, which is a Vidar infostealer. The malware targets 19 different browsers including Chrome, Edge, and Firefox to steal browser-saved passwords, cookies, authenticated sessions, autofill data, and FTP credentials. It uses legitimate browser binaries in headless mode to access protected data, increasing the effectiveness of credential theft. Stolen session tokens enable attackers to bypass two-factor authentication and maintain persistent access to victim accounts. The campaign is timed to exploit the hype and recent leaks of GTA 6 content starting August 18, 2026.

Potential Impact

The malware compromises user credentials and session tokens from multiple browsers, enabling attackers to hijack accounts and access sensitive information without triggering two-factor authentication. This can lead to persistent unauthorized access even after password changes. The theft of FTP credentials and autofill data further increases the risk of broader compromise. The campaign exploits user trust in official-looking promotional sites, increasing the likelihood of infection.

Defensive Guidance

No official patch or fix is applicable as this is a malware campaign leveraging social engineering. Users should avoid downloading software from unofficial or suspicious websites, especially those claiming to offer early access or demos of unreleased games. Security teams should block known malicious domains associated with this campaign and educate users about the risks of fake download sites. Use endpoint protection solutions capable of detecting Vidar infostealer variants. Monitor for unusual authentication activity that may indicate session hijacking.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer"]
Pulse Id
6a8d3fe4a1d4c2fb6cd421c2

Indicators of Compromise

Domain

ValueDescriptionCopy
domainbrr.1001gacor.org
—
domainrex.1001gacor.org
—
domainkra.1001gacor.org
—
domainbob.1001gacor.org
—
domainket.sm188daftar.mom
—
domainljr.1001gacor.org
—
domainzaf.sm188dnsx.top
—
domainzaf.11gokil.org
—
domainsii.sm188dnsx.top
—
domainges.1001gacor.org
—
domainsii.11gokil.org
—
domaintax.11gokil.org
—
domaintax.sm188dnsx.top
—
domainses.1001gacor.org
—
domainket.1001gacor.org
—
domaindez.11gokil.org
—
domainsto.1001gacor.org
—
domainbib.1001gacor.org
—
domainnhg.1001gacor.org
—
domaingta6demo.asia
—
domaingta6demo.eu
—
domaingta6demo.us
—
domainrockstar-gta-6.com
—

Hash

ValueDescriptionCopy
hasha8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0
—
hash8b8f661341a7699e6fc65c8dfdf3af6e
—
hash12456ee7204a782bf776ff5279316c26b33ec762
—

Threat ID: 6a8d73d1acd9273b490ff89c

Added to database: 08/25/2026, 10:52:01 UTC

Last enriched: 09/10/2026, 20:04:06 UTC

Last updated: 10/02/2026, 14:20:54 UTC

Views: 110

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses