A supposed Grand Theft Auto VI demo delivered a 1.1 MB Windows executable that opened no visible window and installed no persistence. It still gave Vidar enough time to copy browser passwords, cookies, and authenticated sessions that may remain useful after the malware is removed.
Malwarebytes identified a network of search-visible sites impersonating Rockstar Games as interest surged around leaked footage and an official August 27 presentation. The observed gta6_installer.exe sample appeared on August 19, one day after fresh leaked material began circulating.
The report comes from Malwarebytes ThreatLabs, which is evaluating a campaign its own products detect and block. No sponsored placement is involved. The company did not quantify downloads, infections, victims, or geographic reach, and it did not attribute the operation.
A 1.1 MB installer delivers Vidar
Rockstar’s official Extended Look announcement describes a video premiering on Netflix before appearing on YouTube and the GTA VI site. The official product page lists PlayStation 5 and Xbox Series X|S. Neither page offers a playable demo or PC build.
The lure sites copied Rockstar’s artwork and promotion, then added Play Now or download controls. Malwarebytes said, “We identified a network of sites appearing in searches for a GTA 6 demo and impersonating Rockstar Games.” A visitor following those controls could receive gta6_installer.exe, a file smaller than a screenshot Malwarebytes captured of one lure page.
Malwarebytes classified the executable as Vidar, an established information stealer sold as a service. Its analysis found 19 browser targets, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. The sample also searched Thunderbird profiles, Perplexity’s Comet browser, the WebView2 browser embedded in Roblox Studio, and credentials stored by FTP clients.
Malwarebytes observed no startup entry, scheduled task, or installed service that would relaunch this sample after reboot. That finding narrows host persistence. It does not erase credentials and session material already sent away.
Browser processes access protected data
The sample used the browsers already trusted on the Windows system. Malwarebytes observed it launch installed Chrome, Edge, and Firefox binaries in headless mode, suppress logging, and point each process at a temporary user-data directory. It then deleted those temporary directories.
This route matters because newer browsers protect credential databases with stronger encryption and application-level controls. The sample worked through a browser process permitted to use its own protected data instead of only copying a database and decrypting it from an unrelated process.

Figure details
The diagram follows one observed sequence. Search-visible fake Rockstar pages deliver the 1.1 MB file gta6_installer.exe. The file runs Vidar, which starts installed Chrome, Edge, and Firefox binaries in headless mode against temporary user-data directories. Vidar extracts saved passwords, cookies, browser-profile data, and authenticated sessions, then sends the collection to attacker infrastructure. The source did not quantify infections or confirm account takeover.
Passwords and cookies create different recovery obligations. A password reset changes the shared secret used at the next login. An active session token records that authentication already succeeded, so some services may accept a stolen token without asking for the password or second factor again. The source reports the theft capability and observed sample behavior; it does not report a confirmed downstream account takeover.
Dead drops rotate attacker infrastructure
Vidar can obtain a current delivery address from attacker-controlled profiles hosted on legitimate shared services. Malwarebytes observed this sample connect to Telegram, Pinterest, and Steam Community pages used as dead-drop resolvers. Those hostnames remain undefanged here because the services are legitimate; the specific attacker-controlled profile paths are detection strings and appear defanged below.
The observed filename and SHA-256 are:
gta6_installer.exea8f19d598e6a49d8510d73d41fc445246755ed321c2f76985a463a9fef537eb0
The distribution domains were gta6demo[.]asia, gta6demo[.]eu, gta6demo[.]us, and rockstar-gta-6[.]com. The dead-drop resolver paths were telegram[.]me/m1duus, t[.]me/m1duus, pinterest[.]com/m1duus, and steamcommunity[.]com/profiles/76561198657426610.
Malwarebytes observed the sample communicate with ses.1001gacor[.]org and ket.sm188daftar[.]mom. It also associated this Vidar infrastructure with the activity: ket.1001gacor[.]org, ljr.1001gacor[.]org, nhg.1001gacor[.]org, bob.1001gacor[.]org, kra.1001gacor[.]org, brr.1001gacor[.]org, sto.1001gacor[.]org, rex.1001gacor[.]org, bib.1001gacor[.]org, ges.1001gacor[.]org, tax.11gokil[.]org, sii.11gokil[.]org, zaf.11gokil[.]org, dez.11gokil[.]org, tax.sm188dnsx[.]top, sii.sm188dnsx[.]top, and zaf.sm188dnsx[.]top.
These values are hunting leads. A domain match alone does not prove execution because some entries describe delivery or resolver infrastructure. Stronger evidence combines the file hash or filename with process creation for a browser in headless mode, temporary browser-profile activity, and outbound traffic close to the same timestamp.
Malwarebytes publishes these detection indicators in its defensive report. Nulltap does not link the lure sites or executable, so this article adds no acquisition path for the live artifact.
Revoke sessions after cleanup
If gta6_installer.exe ran, isolate the Windows device and preserve the executable hash, process telemetry, browser child-process arguments, temporary profile paths, DNS and proxy logs, and account sign-in records before removal. Scan with a trusted security product. From a known-clean device, change the primary email password first, then reset banking, payment, gaming, shopping, social, and identity-linked accounts.
Revoke active sessions and remove unfamiliar devices through each service’s account controls. Review mailbox forwarding rules, recovery addresses, phone numbers, authorized applications, and recent account changes. Enable phishing-resistant multifactor authentication where available, while treating it as protection for future logins rather than evidence that a stolen authenticated session is invalid.
Hunt for the published SHA-256, gta6_installer.exe, the distribution domains, the four resolver paths, and the listed attacker infrastructure. Correlate matches with headless launches of installed browser binaries and unexpected user-data directories. Legitimate connections to Telegram, Pinterest, or Steam Community require the specific profile path and surrounding process evidence before escalation.
Run the verification test from a clean device after host remediation. Change the affected account’s password, use its sign out everywhere or equivalent control, remove unknown devices and authorized apps, then attempt to reuse a previously captured test session in an isolated authorized test account. The expected result is rejection of the old session, a fresh authentication challenge, no unexplained recovery or forwarding changes, and no further endpoint or network matches for the observed Vidar indicators.
A clean host shows that Vidar stopped locally. Invalidated sessions and reviewed account state address what the process already exposed.
