Fake GTA 6 Demo Sites Are Installing a Password Stealer

by 6Charts Team Category: news 6 min read

Malwarebytes ThreatLabs published the analysis on 24 August and we re-verified it at the source. The tell is the size: 1.1 MB, against 44 MB for Rockstar's official pack of still screenshots. We print the four domains and both command and control domains defanged, list exactly what the malware takes, and give the recovery steps in the right order, including the one people skip. Revoking sessions matters because stolen cookies keep working after a password change. We did not visit the sites and no victim count exists.

Fake GTA 6 demo sites are handing out a password stealer. Four domains have been dressed up to look like Rockstar's promotion for the Extended Look, and the file they serve is a piece of commodity malware that empties saved logins out of your browser. The most useful thing in this story is a number. The download is 1.1 MB. Hold on to that and the rest of the scam falls apart on its own. What is happening? CONFIRMED, editor re-verified at the primary source on 25 August 2026. Malwarebytes ThreatLabs published "Fake GTA 6 Extended Look and demo sites deliver an infostealer" on 24 August, written by Stefan Dasic, Sr. Malware Research Engineer and Web Protection Technical Lead. We fetched it ourselves at HTTP 200, 340,434 bytes. Four domains are involved. We are printing them defanged, with the dots broken, so that nothing on this page is clickable: gta6demo[.]asia gta6demo[.]eu gta6demo[.]us rockstar-gta-6[.]com The sites work because they steal the real promotion. Verbatim from the report: "The sites are particularly convincing because they copy Rockstar's genuine promotion for its August 27 extended look at GTA 6." Authentic Rockstar artwork and copy, with fake "Play Now" buttons laid over the top. What does the file actually do? CONFIRMED. The payload is named gta6_installer.exe. Its SHA-256 is a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0. The family is Vidar, an established infostealer that its authors rent out to other criminals. It targets 19 browsers, including Chrome, Edge, Firefox, Brave, Opera and Vivaldi. From those it takes: saved passwords and login details session cookies browsing and download history autofill entries and other saved profile data credentials stored by FTP clients CONFIRMED. The command and control domains, also defanged here, are ses.1001gacor[.]org and ket.sm188daftar[.]mom. The malware finds them using dead-drop resolvers, which are ordinary-looking profiles on Telegram, Pinterest and Steam Community that carry the current address in a profile field. That is how a stealer survives a domain being taken down without the operator having to update anything on the victim's machine. Why the 1.1 MB tells you everything CONFIRMED, verbatim from the report: "The supposed GTA 6 installer is just 1.1 MB." Put that next to something real. Rockstar's own official press screenshot pack for GTA 6 is 46,246,798 bytes, roughly 44 MB, and that is nothing but still images. The thing calling itself a GTA 6 installer is about one fortieth the size of a folder of pictures. FileSizeWhat it contains gta6_installer.exe1.1 MBa Vidar infostealer Rockstar official GTA 6 screenshot pack46,246,798 bytes, about 44 MBstill images only A modern open-world game ships at tens of gigabytes. Even a genuine downloader stub for one would pull a launcher, sign you in and start a very long transfer. Anything that finishes downloading in under a second and then wants to run is doing something other than installing a game. Every image on this page is official Rockstar material, taken from the studio's own character video clips. Nothing on this page comes from leaked material, and we did not view any. Is there a GTA 6 demo? No. This is the part that actually protects people, so we will be blunt about it. There is no GTA 6 demo. There is no GTA 6 early access. There is no playable build available to the public in any form. The Extended Look is a video. Watching it involves no download and no executable. There are exactly two legitimate ways to see the Extended Look on 27 August. Netflix at 3 p.m. ET, which needs a subscription. Rockstar's official YouTube channel and the Grand Theft Auto VI site at 9 p.m. ET, which are free. Anything that asks you to download and run a program is not one of those two things. I already ran it. What now? Work in this order, and pay attention to the second step, because it is the one people skip. Change your passwords from a different, clean device. Doing it on the infected machine hands the new password straight back to the stealer. Sign out of all sessions everywhere. Most large services have a "sign out of all devices" control. Stolen session cookies let somebody stay logged in as you even after you change the password, and they keep working until the sessions are revoked. Changing a password on its own does not do it. Turn on two-factor authentication on email first, then on anything holding money or a payment method. Assume anything saved in the browser is gone. Card details, addresses, anything typed into a form and remembered. Clean or rebuild the machine before you trust it with new credentials. What we could not verify We did not visit the four domains and we will not. Our reporting on this rests on the Malwarebytes analysis, which we read in full at the source. We do not know whether the campaign is still live, and we do not know whether any of the domains have been sinkholed or taken down since the report went up on 24 August. No victim count has been published anywhere by anyone, so we are not going to imply one. Treat the domains as dangerous rather than assuming they have been dealt with. What is and is not established Confirmed (editor re-verified at the primary source, 25 August 2026, HTTP 200 at 340,434 bytes): Malwarebytes ThreatLabs published "Fake GTA 6 Extended Look and demo sites deliver an infostealer" on 24 August 2026, by Stefan Dasic, Sr. Malware Research Engineer and Web Protection Technical Lead. Confirmed: four domains are involved, printed defanged above as gta6demo[.]asia, gta6demo[.]eu, gta6demo[.]us and rockstar-gta-6[.]com. Confirmed: the payload is gta6_installer.exe at 1.1 MB, SHA-256 a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0, and the family is Vidar. Confirmed: it targets 19 browsers including Chrome, Edge, Firefox, Brave, Opera and Vivaldi, and takes saved passwords and logins, session cookies, browsing and download history, autofill and other saved profile data, and FTP client credentials. Confirmed: the command and control domains are ses.1001gacor[.]org and ket.sm188daftar[.]mom, with dead-drop resolvers on Telegram, Pinterest and Steam Community profiles. Confirmed, verbatim from the report: the sites are convincing because they copy Rockstar's genuine promotion for the 27 August extended look, and the supposed installer is just 1.1 MB. Confirmed for scale: Rockstar's own official screenshot pack is 46,246,798 bytes, about 44 MB, of still images. The fake installer is roughly one fortieth of that. Confirmed: there is no GTA 6 demo, no early access and no playable build available to the public. The Extended Look is a video and requires no download. Not known: whether the campaign is still live, and whether any of the four domains have been sinkholed or taken down since 24 August. We did not visit them and we will not. Not known: how many people were affected. No victim count has been published anywhere, and we are not estimating one. We will update this if Malwarebytes or anyone else publishes takedown or victim information, on our news page. In the meantime, if you want to actually play something on a server that exists, our servers list is the safe way to spend the wait.