Warning: Dangerous Malware Disguised as a GTA 6 Demo
The long wait for GTA 6 is leading gamers into traps set by cybercriminals. Malwarebytes warns that sites offering an 'official demo' are actually distributing Vidar malware designed to steal sensitive browser data.

The anticipation for GTA 6 is high, and many gamers, eager to play early, are becoming easy targets for cybercriminals. Malwarebytes has exposed a network of websites impersonating the official Rockstar Games site, claiming to offer an official demo version of the game. Clicking the download button triggers the installation of a file named "gta6_installer.exe," which is, in fact, dangerous malware.
Red Flags
Beyond the fact that Rockstar has never announced a downloadable demo, several technical indicators should alert any gamer:
-
The installation file is only 1.1 MB. Modern AAA games are massive, and compressing them to such a small size is impossible.
-
The screenshot of the fake site is larger than the "installer" itself.
-
A PC version of GTA 6 has not yet been announced.
Sophisticated Malware
Security researchers identified the file as part of the Vidar malware family, which operates on a "malware-as-a-service" (MaaS) model. Its primary function is to steal sensitive information stored in browsers. To bypass encryption, the malware runs legitimate browser executables (like Chrome or Firefox) in a hidden "Headless mode." In this state, the browser decrypts passwords and cookies for the malware, which then exfiltrates the data and deletes its tracks.
The danger extends beyond password theft. By collecting cookies and active session tokens, attackers can hijack accounts even with two-factor authentication enabled, as the connection is already verified. If infected, changing passwords is not enough; users must revoke all active sessions across all devices.
Dead-drop Resolvers
Attackers are using a technique called "Dead-drop resolvers" to stay under the radar. Instead of hardcoding the control server's address, the malware retrieves the current address from legitimate profiles on platforms like Telegram, Steam, or Pinterest. This makes the malware's traffic appear as normal data transfers to trusted sites, allowing it to evade security sniffers.





