Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar Infostealer — Threadlinqs Intelligence
As of 2026-08-24, Fake GTA 6 'Extended Look' and Demo Sites Deliver Vidar Infostealer is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-2132 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Threat actors registered typosquat GTA 6 domains offering a bogus playable demo timed to Rockstar Games' real August 27, 2026 'Extended Look' Netflix premiere. A 'Play Now' button serves a 1.1MB
On or around August 19, 2026 — one day after gameplay footage attributed to a leak-branding group calling itself 'Cyberleek' began circulating online — threat actors stood up a small cluster of typosquat/lookalike domains (gta6demo[.]asia, gta6demo[.]eu, gta6demo[.]us, and rockstar-gta-6[.]com) that impersonate official Rockstar Games GTA 6 promotional pages and offer a fake playable 'demo' download. The lure is timed deliberately: it front-runs Rockstar's confirmed real 'Extended Look' trailer premiere on Netflix on August 27, 2026, so search interest and social sharing around the genuine event drive traffic to the fake sites.
Visitors who click the site's 'Play Now' button are served gta6_installer.exe, a 1.1MB Windows PE (SHA-256 a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0), first observed by Malwarebytes ThreatLabs on August 19, 2026. Running the installer deploys Vidar, a long-running (active since 2018) commodity infostealer sold as malware-as-a-service to a broad affiliate base, which explains why this campaign carries none of the hallmarks of a single named APT and is instead opportunistic, hype-driven crimeware.
Rather than attacking browser encryption directly, the sample launches the legitimately-installed Chrome, Edge, and Firefox executables already present on the victim host in headless/automation mode, using the browsers' own access to their protected-storage APIs to pull saved passwords, session cookies, autofill entries, browsing/download history, and stored logins without needing to defeat OS-level credential encryption itself. Malwarebytes documented targeting across 19 browser targets in total, including Chrome, Edge, Firefox, Brave, Opera, Vivaldi, Perplexity Comet, the Roblox Studio WebView2 runtime, and Thunderbird mail-client profiles, plus separate harvesting of locally stored FTP client credentials.
For command-and-control, the sample follows Vidar's well-documented dead-drop-resolver pattern (MITRE ATT&CK T1102.001): rather than hardcoding a C2 address, it queries attacker-controlled profile pages on legitimate platforms — telegram[.]me/m1duus, t[.]me/m1duus, pinterest[.]com/m1duus, and steamcommunity[.]com/profiles/76561198657426610 — whose page content resolves to the live second-stage C2 endpoint (observed as ses.1001gacor[.]org and ket.sm188daftar[.]mom, backed by a wider round-robin pool of over a dozen additional *.1001gacor[.]org, *.11gokil[.]org, and *.sm188dnsx[.]top subdomains). This lets the operators rotate backend C2 servers freely while the resolver front-ends stay stable and blend into normal social-platform traffic, and stolen data is transmitted out via HTTP multipart POST to whichever C2 endpoint the resolver currently points at.
This is not the first GTA 6 leak-hype scam of 2026: an earlier campaign charged victims directly for bogus 'early access' to the game. The pattern is consistent — threat actors treat every high-visibility GTA 6 media beat (leaks, trailers, premieres) as a fresh social-engineering hook for credential-stealing malware distribution, and can be expected to repeat this playbook around the actual August 27 Netflix premiere and any subsequent official Rockstar marketing beats.
Target sectors: consumer, gaming
Target regions: Global
Timeline
- Rockstar Games suffers the original GTA 6 data breach: a Lapsus$-affiliated hacker ('teapotuberhacker') posts over 90 leaked alpha-footage videos and source-code files to GTAForums.com, establishing GTA 6 leak content as a recurring social-engineering hook that scammers have exploited ever since.
- An earlier, distinct fake-GTA-6-installer infostealer incident (GTA6_Setup_Crack_2026.exe, detected and contained by EDR within 3 minutes 44 seconds of execution) is documented independently by researcher Manubhav Sharma, establishing precedent for the fake-installer-as-infostealer-lure pattern this campaign repeats.
- GTA 6 gameplay footage begins circulating online; a group branding itself 'Cyberleek' is credited with the leak, creating the hype the campaign later exploits.
- Malwarebytes ThreatLabs first observes the trojanized gta6_installer.exe (SHA-256 a8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0) being served from the fake GTA 6 demo/typosquat domains — one day after the leak footage appeared.
- FinalBoss.io publishes a consumer warning about fake 'Cyberleek build' downloads and GTA 6 leak-themed scams distributing malware.
- Malwarebytes publishes technical threat-intel analysis identifying the campaign's Vidar payload, dead-drop-resolver C2 infrastructure, and 19-browser credential-theft scope; Malwarebytes confirms detection and blocking of the sites and infrastructure.
- Rockstar Games' genuine GTA 6 'Extended Look' premieres on Netflix — the real-world event the fake demo sites are timed to ride ahead of and free-ride the search/social traffic from.
- GTA 6's official scheduled retail release date for PlayStation 5 and Xbox Series X|S — the terminal hype milestone this and prior GTA 6-themed malware campaigns are expected to continue exploiting through.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1583.001, T1608.001, T1204.001, T1027, T1622, T1497.001, T1070.004, T1082, T1555.003, T1539