Overview
Cybercriminals are exploiting the hype around Grand Theft Auto VI by distributing a fake demo that installs Vidar information‑stealing malware on Windows devices. Instead of delivering early access to the game, the malicious installer quietly harvests passwords, session cookies, and browser data, putting victims’ personal and financial accounts at risk.
How the Scam Works
- Fake Rockstar websites: Convincing domains mimic Rockstar’s branding and promotional artwork.
- Malicious installer: Clicking “Play Now” downloads a 1.1 MB executable (
gta6_installer.exe)—far too small for a modern AAA game. - Vidar stealer payload: Once executed, it runs silently, collecting saved logins, session cookies, browsing history, and autofill data.
- Targeted browsers: Chrome, Edge, Firefox, Brave, Opera, Vivaldi, plus Thunderbird and Roblox Studio components.
- Session hijacking: Stolen cookies allow attackers to bypass passwords and two‑factor authentication by replaying active sessions.
Why It’s Dangerous
- Beyond gaming accounts: Email, social media, shopping, and payment accounts can all be compromised.
- Session replay risk: Attackers can log in without needing your password.
- Stealthy execution: No visible game window or startup entry—victims may not notice until accounts are abused.
- Observed infrastructure: Malware connected to Telegram, Pinterest, and Steam profiles as dead‑drop resolvers, plus multiple malicious domains.
Indicators of Compromise (IoCs)
- Domains:
gta6demo[.]asia,gta6demo[.]eu,rockstar-gta-6[.]com - File:
gta6_installer.exe(SHA‑256:a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0) - Profiles:
telegram[.]me/m1duus,steamcommunity[.]com/profiles/76561198657426610 - Network infrastructure:
ses.1001gacor[.]org,ket.sm188daftar[.]mom, multiple1001gacorand11gokildomains.
Defensive Guidance
- Avoid unofficial downloads: Rockstar has not released a demo, beta, or early build.
- Scan infected devices: Use trusted anti‑malware tools immediately.
- Reset credentials: Change passwords from a clean device, starting with email and financial accounts.
- Revoke sessions: Sign out everywhere, remove unfamiliar devices, and invalidate active sessions.
- Monitor accounts: Watch for unauthorized logins or transactions.
Expert in the Cloud Insight
This campaign shows how gaming hype can be weaponized. By blending fake branding, small executables, and session cookie theft, attackers bypass traditional defenses and exploit trust in familiar entertainment brands. The lesson is simple: if it’s not from the publisher or an official store, it’s not safe.
Leave a Reply