Skip to content

Safety report / Aug 24, 2026

GTA 6 safety.Fake GTA 6 Demo Sites Spread Password-Stealing Malware

A reported fake GTA 6 demo installed an infostealer targeting passwords, cookies and sessions. Learn the risks and immediate response steps.

Reputable reporting

Reader safety alert

Protect your accountAlertCheck first
Use official sources and avoid downloads, wallet requests and fake demo pages.
EvidenceReputable reporting
PublishedAug 24, 2026
Last verifiedSep 16, 2026
ByAJ · Independent news desk

Reader safety report

Check the claim.
Protect yourself.

Understand the reported risk, use official channels and act carefully if an account or device may be affected.
3D cartoon security shield stopping a suspicious download package
Safety report visualOriginal safety illustration; no malicious address is shown.

There is no official public GTA 6 demo or PC download. Malwarebytes reported on August 24, 2026 that fake websites copying Extended Look branding delivered a Vidar information stealer instead of a game or video.

This is reported security research, not a Rockstar announcement. Malwarebytes analyzed the campaign and the file; Rockstar’s official material establishes that the real Extended Look is a video and that the announced launch platforms are PS5 and Xbox Series X|S.

What researchers observed

Malwarebytes’ original investigation describes imitation Rockstar pages appearing for demo searches. A “Play Now” route delivered a roughly 1.1 MB executable—not a playable game. The researchers identified it as Vidar and observed targeting across 19 browsers. They dated the sample to August 19, during heightened interest in unauthorized footage; their public report followed on August 24.

Those observations describe this investigated sample, not every fake GTA 6 site. Do not use the small file size as the only test: a larger download can also be malicious. The decisive point is that Rockstar has not published a public demo or PC installer.

What the fake installer targeted

According to Malwarebytes, the program searched for browser-stored information including:

  • Saved passwords and login details.
  • Session cookies and authenticated browser sessions.
  • Browsing, download and autofill data.
  • Credentials stored by some other applications.

These risks are related but not identical. A stolen password can be changed. A stolen active session may let an attacker act as though a browser is already signed in, so changing a password alone may not end every session. The file itself also needs to be removed from the affected device.

Malwarebytes reported no persistence mechanism in the sample it analyzed. That does not mean the incident ends after a reboot or scan: information already taken can still be used. It also does not guarantee that a different fake installer behaves the same way.

If you downloaded but did not run the file

Do not open it. Delete or quarantine it with a trusted security product, then scan the device. If you entered credentials on the fake page before downloading, change those credentials from a clean device and check the affected account.

If you ran the fake demo

Assume browser passwords and active sessions on that computer may have been exposed.

  1. Disconnect the affected computer from the network and stop using it for email, payments or password changes.
  2. Use a trusted security product to scan and remove detected malware. If you are unsure how to clean the device, contact a reputable local professional or the security provider through its real website.
  3. From a separate clean device, change the password for your primary email first, then financial, shopping, gaming and social accounts.
  4. Use each important service’s “sign out everywhere” or active-session controls. This addresses stolen sessions as well as passwords.
  5. Check recovery email addresses, phone numbers, forwarding rules, authorized apps and unfamiliar devices for changes you did not make.
  6. Turn on two-factor authentication where available. It improves future protection, although it cannot undo a session that was already stolen.
  7. Monitor payment, email, Steam, Epic, Rockstar and console accounts for unfamiliar activity.

File risk versus account risk

Removing the file deals with the device. Password changes, session revocation and account review deal with information that may already have left the device. Completing only one side can leave the other risk open.

This campaign is different from the later wallet-drainer report. The fake demo required an executable and targeted computer/browser data. The wallet scam centered on wallet connections, approvals and transfers.

How to avoid the lure

A familiar logo, official artwork or correct release date does not make a download legitimate. Go to Rockstar’s own website for videos and announcements. Do not disable security software for an installer, and do not trust a search advertisement simply because it appears above normal results.

We do not publish the malicious domains because that could send readers toward them. Malwarebytes’ linked primary report contains the technical research. The maintained GTA 6 scam-prevention guide covers broader download, beta, preorder and recovery checks.

Sources

We checked these sources before publishing. Official sources are used wherever possible.

  1. Fake GTA 6 Extended Look and demo sites deliver an infostealer — Malwarebytes, checked Sep 16, 2026
  2. Grand Theft Auto VI: An Extended Look — Rockstar Games, checked Sep 16, 2026