Fake GTA 6 Demo Sites Are Cloning the Extended Look Promo

by 6Charts Team Category: news 8 min read

The single most useful fact before tomorrow's premiere is that there is no GTA 6 demo and there never has been, so any site offering one is fraudulent. We re-fetched the Malwarebytes ThreatLabs analysis at HTTP 200 and 340,313 bytes and confirmed from its own timestamps that it has not been edited since publication. The size is the tell: 1.1 MB against 46,246,798 bytes for Rockstar's official pack of still screenshots. We describe the domain pattern rather than listing domains, and we did not visit any of them. No takedown and no victim count has been published by anybody.

There is no Grand Theft Auto VI demo. There has never been one. Rockstar has not announced or released a playable build of the game in any form, to anybody, and any website offering you one is lying to you. That sentence is the whole of the practical advice in this article. Everything below explains what the sites offering a demo are actually handing out, and what to do if you already clicked. What is happening? CONFIRMED at the primary source, re-fetched today. Malwarebytes ThreatLabs published "Fake GTA 6 Extended Look and demo sites deliver an infostealer" by Stefan Dasic. We fetched it at HTTP 200 and 340,313 bytes. Its structured data carries datePublished 2026-08-24T16:51:55+00:00 and dateModified 2026-08-24T16:51:56+00:00. Those are one second apart, which means the analysis has not been edited, corrected or updated since it went up. That is a small confirmed negative and it is worth one line, because a security writeup that has been quietly revised is a different thing from one that has not. The core finding, verbatim from the report: We identified a network of sites appearing in searches for a GTA 6 demo and impersonating Rockstar Games. One Google result advertises an 'Official Download,' but visitors who follow the sites' 'Play Now' links can instead end up downloading gta6_installer.exe. And on why the pages are convincing, verbatim: The sites are particularly convincing because they copy Rockstar's genuine promotion for its August 27 extended look at GTA 6. That is the part that makes this campaign worth a warning the day before the premiere. The pages are wearing Rockstar's real artwork and Rockstar's real copy about tomorrow's broadcast. Looking legitimate is exactly what they are engineered to do, so "it looked official" is not a signal you can use. What does the file do? CONFIRMED, verbatim from the report: It's an information stealer designed to take passwords stored in browsers, cookies, and authenticated sessions. And because stolen browser sessions can sometimes be reused without going through the normal login process, even two-factor authentication (2FA) may not be enough to stop them. Read that last clause twice. Two-factor authentication protects the act of logging in. A stolen session cookie skips the act of logging in. That is why the recovery steps below put session revocation above password changes in importance. The technical details, all safe to print and useful to defenders: Payload filename: gta6_installer.exe Size: 1.1 MB SHA-256: a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0 Malware family: Vidar, an established commodity infostealer that its authors rent out Browsers targeted: 19 Dead-drop resolvers hosted on Telegram, Pinterest and Steam Community profiles Dead-drop resolvers are the operational detail worth understanding. Rather than hard-coding a server address into the malware, the operator puts the current address into an innocuous-looking profile field on a mainstream platform. The malware reads the profile, learns where to report, and keeps working even after the original address is taken down. It is why "that domain has been seized" is weaker reassurance than it sounds. Malwarebytes dates the first Cyberleek-themed material in this campaign to 18 August and the first malicious sample to 19 August. The size is the tell CONFIRMED, verbatim from the report: The executable delivered by these sites is just 1.1 MB. That is nowhere near enough to contain a modern AAA game. In fact, the screenshot we took of one of the websites is larger than the file it was offering. Put that next to something real. Rockstar's own official press screenshot bundle for Grand Theft Auto VI is 46,246,798 bytes, roughly 44 MB, and it contains nothing but still images. A file claiming to be the game itself is about one fortieth the size of a folder of pictures of it. A modern open-world game ships at tens of gigabytes. Even a genuine downloader stub would open a launcher, sign you in and start a very long transfer. Anything that finishes downloading in under a second and then asks for permission to run is doing something other than installing a game. How do I recognise these sites? We are describing the pattern rather than listing the domains, because the pattern is what you can actually use. A list goes stale within days. We did not visit any of these sites and we are not going to. The pattern reported by Malwarebytes is short domains assembled from the obvious words. The game's abbreviated name joined to the word demo, on an unusual top-level domain. Or the studio's name hyphenated together with the game's name and number. They surface in search results, sometimes as paid placements, and at least one advertises an "Official Download". The reliable checks, in order: There is no demo. If a page offers one, it is fraudulent, whatever it looks like. Rockstar publishes on its own site and its own Newswire. A domain that merely contains the word rockstar is not Rockstar. Watching a video never requires an executable. The Extended Look is a video. A search result is not a verification. Paid placement puts fraudulent pages above genuine ones routinely. I already ran it. What now? Work through these in order. The second one is the one people skip and it is the one that matters most. Change your passwords from a different, clean device. Doing it on the infected machine hands the new password straight back to the stealer. Sign out of all sessions everywhere. Most large services have a "sign out of all devices" control. Stolen session cookies let somebody stay logged in as you after you have changed the password, and they keep working until the sessions are revoked. Changing a password alone does not do it. Turn on two-factor authentication on your email first, then on anything holding money or a saved payment method. It will not undo a stolen session, but it raises the cost of the next attempt. Assume anything saved in the browser is gone. Card details, addresses, anything typed into a form and remembered. Clean or rebuild the machine before you trust it with new credentials. Expect fake stream links tomorrow, as a precaution We want to be careful with this section, because it is forward-looking and nothing in it is a reported incident. No fake-stream scam timed to tomorrow's broadcast has been documented by any vendor. We are not telling you one exists. What we are telling you is that a premiere with this much attention, running in two windows six hours apart, with a large audience that cannot watch the first one, is an obvious setup for pages promising an "early stream" or a "leaked link". Treat that as a reasonable precaution rather than as a warning about something we have seen. The three legitimate places to watch are Netflix at 3 p.m. ET, and the official Rockstar Games YouTube channel and the Grand Theft Auto VI site at 9 p.m. ET. Nothing to download. Nothing to install. No demo exists. What we could not verify Whether the campaign is still live. No vendor, CERT or security outlet has reported a takedown or a sinkhole. Our researcher swept BleepingComputer, The Record, The Hacker News, ESET, Bitdefender, Kaspersky, Sophos, Trend Micro, Cloudflare, CISA and the NCSC and found no 2026 advisory on this at all, only coverage of the 2022-era incident. The tier-one security press has not covered this campaign. Treat the infrastructure as live. How many people were affected. No victim count has been published anywhere by anybody, so we are not implying one. Whether a second campaign exists. Two writeups describing a different loader variant were blocked to us at HTTP 403 and we could not read them. That is unconfirmed and we are flagging it rather than building on it. A caution for other outlets. An automated scan of one aggregator's coverage appears to surface a fresh SHA-256 that looks like a second sample. It is not a malware hash. It is the hash in the article author's avatar address. We are not republishing it, and anybody adding it to a blocklist would be blocking nothing. What is and is not established Confirmed at the primary source (HTTP 200 at 340,313 bytes): Malwarebytes ThreatLabs, "Fake GTA 6 Extended Look and demo sites deliver an infostealer", by Stefan Dasic, datePublished 2026-08-24T16:51:55+00:00. Confirmed negative: dateModified is 2026-08-24T16:51:56+00:00, one second after publication, so the analysis has not been edited or corrected since it went up. Confirmed, verbatim: the sites impersonate Rockstar Games, appear in searches for a GTA 6 demo, advertise an "Official Download", and deliver gta6_installer.exe from "Play Now" links. Confirmed, verbatim: the payload is an information stealer that takes browser-stored passwords, cookies and authenticated sessions, and stolen sessions can sometimes be reused without a normal login, so two-factor authentication may not be enough to stop them. Confirmed: the payload is 1.1 MB, SHA-256 a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0, family Vidar, 19 browsers targeted, with dead-drop resolvers on Telegram, Pinterest and Steam Community profiles. Confirmed: Malwarebytes dates the first Cyberleek-themed material in this campaign to 18 August and the first malicious sample to 19 August. Confirmed, verbatim: "Rockstar has not announced or released a demo of Grand Theft Auto VI." Confirmed for scale: Rockstar's own official screenshot bundle is 46,246,798 bytes of still images. The fake installer is roughly one fortieth of that. Not verified: whether the campaign is still live or whether anything has been sinkholed. No vendor, CERT or security outlet has reported a takedown, and a sweep of eleven major security publishers and agencies found no 2026 advisory at all. Not verified: any victim count. None has been published anywhere and we imply no number. Unconfirmed: whether a second, distinct campaign with a different loader variant exists. Two writeups describing one were blocked to us at HTTP 403. A precaution, not a reported incident: fake "live stream" links timed to the 27 August premiere. No vendor has documented one and we are not claiming that any exists. Editorial policy: we did not visit any of the malicious sites and we are not listing the domains. We describe the pattern instead, because a pattern stays useful after a list goes stale. If a takedown, a sinkhole or a victim count is published by anybody credible, we will report it on our news page. In the meantime, the safest thing you can do with the next twenty-four hours is spend them on our servers list rather than on a search results page.