-
Scammers built fake Rockstar Games sites that promise a playable GTA 6 demo, but the download is malware instead.
-
The malware steals saved passwords, browser cookies, and login sessions, and it can slip past two-factor authentication.
-
Rockstar has not released any GTA 6 demo. Its real Extended Look premieres on Netflix on August 27.
Grand Theft Auto 6 footage leaked online this month, and Rockstar has a real Extended Look coming to Netflix on August 27.
Scammers saw the excitement and used it. According to media reports, fake Rockstar sites now push a file that steals passwords instead of delivering a game.
There is no real GTA 6 demo
Rockstar has not released or announced any playable demo for GTA 6. The game arrives on November 19, 2026, for PlayStation 5 and Xbox Series X|S. Rockstar has not confirmed a PC version either.
Rockstar only confirmed one thing: an Extended Look at GTA 6. It airs on Netflix on August 27, then moves to Rockstar’s YouTube channel later that day. That is a video, not a downloadable demo.
Fake sites copy this real announcement closely. They use similar artwork and wording. Then they add a “Play Now” button that real Rockstar pages don’t have. One site even called its file an “Official Download,” Malwarebytes noted. Fans who click that button don’t get a game. They get a file named gta6_installer.exe.
The file size gives the scam away fast. It weighs just 1.1 MB. A modern blockbuster game needs far more space than that. Malwarebytes said a screenshot of one scam site took up more storage than the file it was offering.
This isn’t the first fake GTA 6 offer either. Scammers charged fans hundreds of dollars for fake early access earlier this year, Malwarebytes said.
Leaked footage opened the door for scammers
New gameplay clips and a map of the game’s setting, Leonida, spread online on August 18. A group calling itself Cyberleek claimed credit. Rockstar and its parent company, Take-Two, moved fast to remove the material. Take-Two also filed legal requests with Microsoft and Discord to try to identify the leakers.
Source code in X’s app suggests it may be developing mandatory facial verification using Amazon Rekognition face liveness. The potential feature has raised privacy concerns, although X has not confirmed its rollout.
The fake installer showed up just one day later, on August 19. Genuine unofficial clips were already spreading, so people searching for more leaks had reason to think other files online might be real too.
Not everything tied to the leak was genuine, though. Some leaked clips carried ads for a cryptocurrency coin linked to Cyberleek. The group’s own site also asked for crypto donations and sold ad space in future GTA 6 videos. Some clips shared as new leaks were actually old footage or AI-generated fakes, Malwarebytes said.
GTA 6 has faced a major leak before. Rockstar confirmed in 2022 that an attacker stole and posted early development footage. Big leaks tend to draw big crowds, and scammers use that crowd to spread malware.
The malware steals passwords and active logins
The file belongs to a well-known malware family called Vidar, according to Malwarebytes. Criminals rent Vidar out as a ready-made tool, so many different attackers can use it. Malwarebytes said its own software already detects this file and blocks the sites spreading it.
Vidar hunts for anything a browser remembers for you. That includes saved passwords, autofill details, browsing history, and login cookies. Malwarebytes found it searched 19 browsers, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also checked Thunderbird, Perplexity’s Comet browser, and the browser built into Roblox Studio.
The malware doesn’t install anything that stays after a restart, Malwarebytes reported. But it doesn’t need to stay. Once it grabs a password or login cookie, attackers can use that data even after removing the malware. Victims may not notice anything happened at all, since the program opens no visible window.
This is why the threat goes beyond passwords. A login cookie tells a website you already signed in, so you skip re-entering your password each visit. If a thief steals that cookie, they may reuse your active session directly, according to Malwarebytes.
Two-factor authentication guards the login step, but a stolen cookie was created after that step already succeeded. So changing your password alone might not lock attackers out. You should also sign out of every device from your account settings.
How to stay safe
Only download games from official stores such as Steam, the Epic Games Store, or console marketplaces. Never trust a “demo” for a game that hasn’t launched. Check file size before opening anything, since a one-megabyte file cannot hold a real game. Avoid unofficial leak sites entirely, since there is no way to confirm which files on them are safe.
If you already ran the file, scan your device with trusted security software right away. Then change your passwords from a clean device, starting with your email. Sign out of all active sessions on every account you can. Watch your accounts closely for a few weeks afterward.