The huge excitement surrounding Grand Theft Auto VI (GTA VI) is turning into an opportunity for cybercriminals, who are attempting to trap unsuspecting players with a supposed demo of the highly anticipated title. Behind the fake download pages is not an early version of the game, but the notorious malware Vidar Stealer, designed to steal passwords and active sessions from Windows computers.
The campaign is taking advantage of the hype surrounding GTA VI, new information about the game, and leaked footage that has been circulating online. Attackers are exploiting users' curiosity to lead them to websites that appear to be official Rockstar Games.
The non-existent GTA VI demo that leads to malware
Malwarebytes detected the campaign and found that the websites in question use familiar graphics, terminology, and promotional material that refer to GTA VI. Buttons such as “ Download ” and “ Play Now ” create the impression that the visitor can gain early access to the game.
In fact, the download ends up with a malicious executable file. In fact, the installer is around 1.1 MB, which is a significant indication of risk for a modern title of this scale.
See also: Gamescom 2026: The great gaming festival returns with impressive revelations
Timing also appears to be part of the strategy. The sample was detected on August 19th, just one day after a surge in new unauthorized material allegedly related to the game. The perpetrators thus exploited an already “hot” topic to attract users.

What does the Vidar Stealer steal?
The malware isn't just interested in a gamer's account. It can look for saved passwords, cookies, browsing history, autofill data, and information from FTP clients.
This particular version targeted data from 19 different browsers, including Chrome, Edge, Firefox, Brave, Opera , and Vivaldi. It also sought information from Thunderbird, Comet , and data related to Roblox Studio.
This means that a victim can lose access not only to gaming services, but also to email, social media, online stores , and other online services they use every day.
The biggest risk is session cookies
Of particular concern is the possibility of stealing session cookies. This is data used by websites to recognize that a user is already logged in.
If such a cookie remains active and is exploitable by the attacker, it can in some cases allow access to an account without having to re-enter the password or perform a new two-factor authentication process.
Therefore, simply changing your password after an infection is not necessarily enough. You also need to terminate active sessionsto revoke the stolen access tokens.
See also: GTA VI: A game that is in its own universe!
How it works silently
Vidar is designed to reduce the amount of evidence that could raise suspicion. Researchers found that the malware can launch genuine applications like Chrome, Edge, and Firefox in stealth mode in order to access stored information.
At the same time, it uses temporary folders and then tries to remove traces of its activity. To communicate with the perpetrators' infrastructure, links related to services such as Telegram, Pinterest and Steam have also been observed, which can act as changing pointers to final destinations.

What should potential victims do?
Anyone who downloaded or ran this "demo" should treat their computer as potentially compromised. First, a full scan with reliable security software and, ideally, important passwords should be changed from a clean device.
Priority should be given to email, financial accounts , and services used to recover other accounts. At the same time, it is necessary to log out of all active sessions, remove unknown devices and applications, and check recovery data.
See also: Horizon 3: When will we play the new game?
"Early access" is the trap
To date, there is no official downloadable demo, beta, or PC version of GTA VI offered in this manner. This is the most important thing for players to remember.
The desire for early access, exclusive content, or leaked builds has become a social engineering tool. Criminals don't need to convince the user to install an unknown program; they just need to offer them what they're already looking for.
The safest rule remains simple: download only from official sources and pay special attention to search ads, leaks, and supposed demos. In the world of gaming, a highly anticipated game can become just as effective bait as any phishing email.
