Fake GTA 6 Extended Look and demo sites deliver an infostealer
Description
Cybercriminals are exploiting the hype around Grand Theft Auto VI by creating fake websites that impersonate official Rockstar Games promotional material. These sites offer a GTA 6 demo download which is actually a Vidar infostealer malware. The malware steals sensitive browser data including passwords, cookies, session tokens, autofill data, and FTP credentials from multiple browsers. It uses legitimate browser binaries in headless mode to bypass protections and steal data more effectively. Stolen session tokens can bypass two-factor authentication, allowing persistent unauthorized access even after password changes. This campaign leverages recent GTA 6 leaks to lure victims.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves fake websites impersonating Rockstar Games to distribute a malicious executable named gta6_installer.exe, which is a Vidar infostealer. The malware targets 19 different browsers including Chrome, Edge, and Firefox to steal browser-saved passwords, cookies, authenticated sessions, autofill data, and FTP credentials. It uses legitimate browser binaries in headless mode to access protected data, increasing the effectiveness of credential theft. Stolen session tokens enable attackers to bypass two-factor authentication and maintain persistent access to victim accounts. The campaign is timed to exploit the hype and recent leaks of GTA 6 content starting August 18, 2026.
Potential Impact
The malware compromises user credentials and session tokens from multiple browsers, enabling attackers to hijack accounts and access sensitive information without triggering two-factor authentication. This can lead to persistent unauthorized access even after password changes. The theft of FTP credentials and autofill data further increases the risk of broader compromise. The campaign exploits user trust in official-looking promotional sites, increasing the likelihood of infection.
Defensive Guidance
No official patch or fix is applicable as this is a malware campaign leveraging social engineering. Users should avoid downloading software from unofficial or suspicious websites, especially those claiming to offer early access or demos of unreleased games. Security teams should block known malicious domains associated with this campaign and educate users about the risks of fake download sites. Use endpoint protection solutions capable of detecting Vidar infostealer variants. Monitor for unusual authentication activity that may indicate session hijacking.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer"]
- Pulse Id
- 6a8d3fe4a1d4c2fb6cd421c2
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainbrr.1001gacor.org | — | |
domainrex.1001gacor.org | — | |
domainkra.1001gacor.org | — | |
domainbob.1001gacor.org | — | |
domainket.sm188daftar.mom | — | |
domainljr.1001gacor.org | — | |
domainzaf.sm188dnsx.top | — | |
domainzaf.11gokil.org | — | |
domainsii.sm188dnsx.top | — | |
domainges.1001gacor.org | — | |
domainsii.11gokil.org | — | |
domaintax.11gokil.org | — | |
domaintax.sm188dnsx.top | — | |
domainses.1001gacor.org | — | |
domainket.1001gacor.org | — | |
domaindez.11gokil.org | — | |
domainsto.1001gacor.org | — | |
domainbib.1001gacor.org | — | |
domainnhg.1001gacor.org | — | |
domaingta6demo.asia | — | |
domaingta6demo.eu | — | |
domaingta6demo.us | — | |
domainrockstar-gta-6.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hasha8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0 | — | |
hash8b8f661341a7699e6fc65c8dfdf3af6e | — | |
hash12456ee7204a782bf776ff5279316c26b33ec762 | — |
Threat ID: 6a8d73d1acd9273b490ff89c
Added to database: 08/25/2026, 10:52:01 UTC
Last enriched: 09/10/2026, 20:04:06 UTC
Last updated: 10/02/2026, 14:20:54 UTC
Views: 110
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.