Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar Infostealer

Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar (TL-2026-2132) is a high-severity malware campaign, first published 2026-08-24. It has no confirmed attribution, affects Multiple Web browsers and mail clients targeted for credential/session, maps to 14 MITRE ATT&CK techniques (T1005, T1027, T1070.004), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-2132

Threat ID
TL-2026-2132
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-08-24
Last reviewed
2026-08-24
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
consumer, gaming
Target regions
Global
Detection rules
9
Indicators of compromise
29

Malware and tooling in Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar

Malware and tooling: Vidar

Threat actors registered typosquat GTA 6 domains offering a bogus playable demo timed to Rockstar Games' real August 27, 2026 'Extended Look' Netflix premiere. A 'Play Now' button serves a 1.1MB trojanized installer (gta6_installer.exe) that deploys the Vidar infostealer, which drives the victim's own installed Chrome, Edge, and Firefox binaries headlessly to harvest passwords, session cookies, autofill data, browsing history, and FTP credentials across 19 browsers, then exfiltrates the loot to Vidar C2 infrastructure reached via Telegram/Steam/Pinterest dead-drop resolver profiles.

How Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar works

On or around August 19, 2026 — one day after gameplay footage attributed to a leak-branding group calling itself 'Cyberleek' began circulating online — threat actors stood up a small cluster of typosquat/lookalike domains (gta6demo[.]asia, gta6demo[.]eu, gta6demo[.]us, and rockstar-gta-6[.]com) that impersonate official Rockstar Games GTA 6 promotional pages and offer a fake playable 'demo' download. The lure is timed deliberately: it front-runs Rockstar's confirmed real 'Extended Look' trailer premiere on Netflix on August 27, 2026, so search interest and social sharing around the genuine event drive traffic to the fake sites.

Visitors who click the site's 'Play Now' button are served gta6_installer.exe, a 1.1MB Windows PE (SHA-256 a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0), first observed by Malwarebytes ThreatLabs on August 19, 2026. Running the installer deploys Vidar, a long-running (active since 2018) commodity infostealer sold as malware-as-a-service to a broad affiliate base, which explains why this campaign carries none of the hallmarks of a single named APT and is instead opportunistic, hype-driven crimeware.

Rather than attacking browser encryption directly, the sample launches the legitimately-installed Chrome, Edge, and Firefox executables already present on the victim host in headless/automation mode, using the browsers' own access to their protected-storage APIs to pull saved passwords, session cookies, autofill entries, browsing/download history, and stored logins without needing to defeat OS-level credential encryption itself. Malwarebytes documented targeting across 19 browser targets in total, including Chrome, Edge, Firefox, Brave, Opera, Vivaldi, Perplexity Comet, the Roblox Studio WebView2 runtime, and Thunderbird mail-client profiles, plus separate harvesting of locally stored FTP client credentials.

For command-and-control, the sample follows Vidar's well-documented dead-drop-resolver pattern (MITRE ATT&CK T1102.001): rather than hardcoding a C2 address, it queries attacker-controlled profile pages on legitimate platforms — telegram[.]me/m1duus, t[.]me/m1duus, pinterest[.]com/m1duus, and steamcommunity[.]com/profiles/76561198657426610 — whose page content resolves to the live second-stage C2 endpoint (observed as ses.1001gacor[.]org and ket.sm188daftar[.]mom, backed by a wider round-robin pool of over a dozen additional *.1001gacor[.]org, *.11gokil[.]org, and *.sm188dnsx[.]top subdomains). This lets the operators rotate backend C2 servers freely while the resolver front-ends stay stable and blend into normal social-platform traffic, and stolen data is transmitted out via HTTP multipart POST to whichever C2 endpoint the resolver currently points at.

This is not the first GTA 6 leak-hype scam of 2026: an earlier campaign charged victims directly for bogus 'early access' to the game. The pattern is consistent — threat actors treat every high-visibility GTA 6 media beat (leaks, trailers, premieres) as a fresh social-engineering hook for credential-stealing malware distribution, and can be expected to repeat this playbook around the actual August 27 Netflix premiere and any subsequent official Rockstar marketing beats.

MITRE ATT&CK techniques used in TL-2026-2132

Collection

T1005 Data from Local System

Defense Evasion

T1027 Obfuscated Files or Information; T1070.004 Indicator Removal: File Deletion; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1622 Debugger Evasion

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1102.001 Web Service: Dead Drop Resolver

Discovery

T1082 System Information Discovery

Execution

T1204.001 Malicious Link

Credential Access

T1539 Steal Web Session Cookie; T1552.001 Unsecured Credentials: Credentials In Files; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1608.001 Stage Capabilities: Upload Malware

Affected products and versions in Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar

  • Multiple — Web browsers and mail clients targeted for credential/session harvesting: Chrome, Microsoft Edge, Firefox, Brave, Opera, Vivaldi, Perplexity Comet, Roblox Studio WebView2, Thunderbird
    Vulnerable versions: any version storing credentials/sessions via the browser's native protected-storage mechanism

Remediation for Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar

Immediate actions

  • Block the distribution domains gta6demo[.]asia, gta6demo[.]eu, gta6demo[.]us, and rockstar-gta-6[.]com at DNS/web proxy
  • Block the C2 and dead-drop infrastructure (ses.1001gacor[.]org, ket.sm188daftar[.]mom, all *.1001gacor[.]org, *.11gokil[.]org, and *.sm188dnsx[.]top subdomains) at network egress
  • Alert on and quarantine files matching SHA-256 a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0 (gta6_installer.exe)
  • Force password resets and full session/cookie invalidation for any host confirmed to have executed gta6_installer.exe

Workarounds

  • Only download GTA 6 content from Rockstar Games' official site/launcher or the official Netflix premiere channel; treat every unofficial 'Play Now'/'demo' download as hostile

Longer-term hardening

  • Deploy EDR behavioral detection for unattended/automation-flagged launches of installed browser binaries (headless Chrome/Edge/Firefox spawned by a non-browser parent process)
  • Run user-awareness messaging ahead of high-hype game/media releases warning against third-party 'demo' or 'early access' downloads
  • Prefer dedicated OS-independent password managers over browser-native credential storage to reduce single-artifact credential exposure

Timeline of Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar

  • Rockstar Games suffers the original GTA 6 data breach: a Lapsus$-affiliated hacker ('teapotuberhacker') posts over 90 leaked alpha-footage videos and source-code files to GTAForums.com, establishing GTA 6 leak content as a recurring social-engineering hook that scammers have exploited ever since.
  • An earlier, distinct fake-GTA-6-installer infostealer incident (GTA6_Setup_Crack_2026.exe, detected and contained by EDR within 3 minutes 44 seconds of execution) is documented independently by researcher Manubhav Sharma, establishing precedent for the fake-installer-as-infostealer-lure pattern this campaign repeats.
  • GTA 6 gameplay footage begins circulating online; a group branding itself 'Cyberleek' is credited with the leak, creating the hype the campaign later exploits.
  • Malwarebytes ThreatLabs first observes the trojanized gta6_installer.exe (SHA-256 a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0) being served from the fake GTA 6 demo/typosquat domains — one day after the leak footage appeared.
  • FinalBoss.io publishes a consumer warning about fake 'Cyberleek build' downloads and GTA 6 leak-themed scams distributing malware.
  • Malwarebytes publishes technical threat-intel analysis identifying the campaign's Vidar payload, dead-drop-resolver C2 infrastructure, and 19-browser credential-theft scope; Malwarebytes confirms detection and blocking of the sites and infrastructure.
  • Rockstar Games' genuine GTA 6 'Extended Look' premieres on Netflix — the real-world event the fake demo sites are timed to ride ahead of and free-ride the search/social traffic from.
  • GTA 6's official scheduled retail release date for PlayStation 5 and Xbox Series X|S — the terminal hype milestone this and prior GTA 6-themed malware campaigns are expected to continue exploiting through.

Sources cited for Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar

More in malware

Detection coverage for TL-2026-2132

As of 2026-08-24, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2132 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats