Is There a GTA 6 Demo? No, and the File Pretending to Be One Defeats Your 2FA

by 6Charts Team Category: news 8 min read

The tell is the file size. 1.1 MB, against 44 MB for Rockstar's official pack of still screenshots. Malwarebytes reports that the sample launches your own Chrome, Edge and Firefox binaries headless with logging disabled to defeat app-bound cookie encryption, installs no persistence of any kind, and appears from your side to do nothing at all. We name no domains, we could not corroborate the indicators independently because URLhaus now returns HTTP 401, and we give the remediation steps in the order that actually works. Revoking active sessions is step two for a reason.

There is no GTA 6 demo. Rockstar has not announced one, has not released one, and nothing playable exists for the public in any form. Every site currently offering a GTA 6 demo download is offering something else, and Malwarebytes reports that at least one family of them is handing out an infostealer that walks straight past two-factor authentication. The single most useful fact in this story is a file size. The executable is 1.1 MB. Hold on to that number and the entire scam falls apart before you have to think about anything else. Is there a GTA 6 demo? No. Malwarebytes puts it about as plainly as it can be put, verbatim from its ThreatLabs report: There is no GTA 6 demo. Rockstar has not announced or released a demo of Grand Theft Auto VI. There is no early access. There is no beta. There is no PC build. The Extended Look is a video, and watching a video involves no download and no executable of any kind. Sourcing, stated up front. The technical analysis in this article is single-sourced to Malwarebytes ThreatLabs, whose post "Fake GTA 6 Extended Look and demo sites deliver an infostealer" we fetched this morning at HTTP 200, 340,196 bytes, against 340,434 bytes when we first read it on 25 August. We tried to corroborate the indicators independently through URLhaus and received HTTP 401, because abuse.ch now requires an authentication key. So we hold no independent confirmation of the technical detail below. We write "Malwarebytes reports" throughout for that reason. Why do the fake sites look so convincing? Because they copy the real promotion. Malwarebytes, verbatim: The sites are particularly convincing because they copy Rockstar's genuine promotion for its August 27 extended look at GTA 6. But the executable they deliver isn't a demo, game, or video. Genuine Rockstar artwork, genuine Rockstar copy, and a fake button laid over the top. The real campaign is doing the persuading. We are naming no domains, defanged or otherwise. Malwarebytes did not publish them in its post body either, and printing a list of malicious hosts on a page read by people who are actively looking for a GTA 6 download would be an odd way to protect anyone. How can you tell from the file size? Malwarebytes makes the comparison itself, verbatim: The file size should also immediately raise suspicion. The executable delivered by these sites is just 1.1 MB. That is nowhere near enough to contain a modern AAA game. In fact, the screenshot we took of one of the websites is larger than the file it was offering. Put it next to something real that we measured ourselves. FileSizeWhat is inside it The fake "GTA 6 installer"1.1 MBan infostealer, per Malwarebytes Rockstar's official GTA 6 press screenshot pack46,246,798 bytes, about 44 MBstill images and nothing else A modern open-world console gametens of gigabytesthe actual game The thing calling itself a GTA 6 installer is roughly one fortieth the size of a folder of Rockstar's pictures. We re-checked the screenshot pack this morning and its size is unchanged. What does the file actually do? Malwarebytes attributes it to Vidar, and describes the family, verbatim: "The installer belongs to the Vidar family, a well-established infostealer ... sold as a service to cybercriminals." On what it targets, verbatim: Our analysis showed 19 browser targets, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also searched Thunderbird profile directories and targeted Perplexity's Comet browser and the WebView2 browser embedded inside Roblox Studio. Per Malwarebytes, what it takes is: saved passwords and login details session cookies browsing and download history autofill entries and other saved browser profile data credentials stored by FTP clients The mechanism is the interesting part. Malwarebytes reports that the sample launched the victim's own real Chrome, Edge and Firefox binaries in headless mode, with logging disabled, pointed at a temporary profile, in order to defeat Chromium's app-bound cookie encryption. The browser decrypts its own cookies, because it is the browser, and the malware collects the output. It is silent throughout. No visible window. Nothing installed that a user would notice. No persistence, no startup entry, no scheduled task, no service. From the victim's side, the file appears to do nothing at all, which is precisely why people run it, see nothing happen, shrug, and move on. Every image on this page is official Rockstar material. Nothing on this page comes from leaked material, and we did not view any. Why does two-factor authentication not protect you? Because the theft happens after the login, not during it. This is the part most coverage of infostealers skips, and it is the reason this article exists. Malwarebytes, verbatim: 2FA protects the login process, but a stolen session was created after that login had already succeeded... This is why changing your password after a stealer infection may not be enough by itself. A password change does not necessarily invalidate every existing session. A session cookie is the token your browser holds once you are already signed in. Someone holding a copy of it is already inside, so there is no login for a second factor to guard. And on many services, changing your password does not kill the sessions that already exist. The step that actually works is revoking active sessions. Most large services call it "sign out everywhere" or "sign out of all devices" and bury it in security settings. That is the control that turns a stolen cookie into a worthless string. I ran it. What do I do now? Work in this order. Step two is the one people skip and it is the one that matters most. Scan and remediate the machine before you trust it with anything new. Revoke all active sessions on every important account. Sign out everywhere. This is what defeats the stolen cookies. Change your passwords from a clean device, email first. Changing them on the infected machine hands the new password straight back. Audit the settings an attacker leaves behind: mail forwarding rules, recovery addresses, authorised third-party apps, and any unfamiliar device in your session list. Enable two-factor authentication where you do not already have it. It does not undo this, and it raises the cost of the next attempt. Keep monitoring for weeks. Stolen credentials are frequently sold on rather than used immediately. Check your gaming accounts specifically. They hold saved payment methods and tradable inventories, and they are often the last place people look. When did this start? Malwarebytes reports that it first observed the executable on 19 August, one day after material attributed to a group calling itself Cyberleek began spreading. The campaign has been running for over a week, which is roughly the period in which search interest in GTA 6 downloads has been climbing towards tonight. A .edu in the URL is not a safety signal A separate observation of our own, and we are labelling its limits carefully. CONFIRMED as to what appears in search results, UNVERIFIED as to intent or ownership: searches on GTA 6 leak terms surface GTA-6-titled pages hosted on subdomains of legitimate institutions, including universities and a major publisher. We did not visit any of them, and we are naming no hosts. The likeliest explanation is compromised or abused infrastructure rather than anything those institutions did deliberately, and we cannot demonstrate that from search listings alone. The practical point stands on its own: a recognisable domain in a URL tells you nothing about what is being served from it. Where can you safely watch the Extended Look? Three channels, and nothing else. ChannelWhenCost Netflix19:00 UTC Thursday 27 Augustsubscription required Official Rockstar Games YouTube channel01:00 UTC Friday 28 Augustfree rockstargames.com/VI01:00 UTC Friday 28 Augustfree Anything else is not a legitimate channel. No early access, no mirror, no demo, no beta, no PC build, no "leaked full version". If a page asks you to download and run a program to watch a video, that is the whole tell. What is and is not established Confirmed: there is no GTA 6 demo, no early access and no playable build available to the public. Malwarebytes states this directly and no storefront lists anything of the kind. Reported by Malwarebytes, single-sourced: fake GTA 6 demo and Extended Look sites deliver a 1.1 MB executable from the Vidar infostealer family, targeting 19 browsers including Chrome, Edge, Firefox, Brave, Opera and Vivaldi, plus Thunderbird profile directories, Perplexity's Comet browser and the WebView2 browser inside Roblox Studio. Source fetched at HTTP 200, 340,196 bytes. No independent corroboration: we attempted to check the indicators against URLhaus and received HTTP 401, because abuse.ch now requires an authentication key. We hold no second source on the technical analysis. Reported by Malwarebytes: the sample launches the victim's own Chrome, Edge and Firefox binaries headless with logging disabled against a temporary profile, to defeat app-bound cookie encryption, and installs no persistence, no startup entry, no scheduled task and no service. Confirmed for scale, re-checked this morning: Rockstar's official press screenshot pack is 46,246,798 bytes, about 44 MB, of still images. The fake installer is roughly one fortieth of that. Reported by Malwarebytes: the executable was first observed on 19 August, one day after material attributed to a group calling itself Cyberleek began spreading. Confirmed as to search results, unverified as to intent: GTA-6-titled pages appear on subdomains of legitimate institutions including universities and a major publisher. We did not visit them and we name no hosts. Not known: how many people were affected, and whether the campaign is still live. No victim count has been published by anyone and we are not estimating one. Editorial policy: no malicious domain appears on this page, defanged or otherwise, and nothing on this page links anywhere near this campaign. We will update this on our news page if takedown or victim information is published. If you want to actually play something on a server that exists, our servers list is a much better use of tonight.