Skip to content
GTA6 LIFE

J−82

Established press

GTA 6 has no demo: four fake sites steal saved passwords

Malwarebytes published its analysis of the campaign on August 24, 2026. Four domains dressed up as Rockstar Games offer a GTA 6 demo that does not exist, and deliver a 1.1 MB credential stealer instead.

GTA6 LIFE

Visit Leonida postcard for the Keys, aerial view of an island strip and a moored seaplane
The official Leonida Keys postcard, issued by Rockstar alongside the screenshots. © Rockstar Games. Official asset used for editorial illustration.

Malwarebytes named four domains on August 24, 2026 that dress themselves up as Rockstar Games and hand out a credential stealer: gta6demo[.]asia, gta6demo[.]eu, gta6demo[.]us and rockstar-gta-6[.]com. The pages lift the promotional material from the An Extended Look announcement, and their Play Now button downloads a file named gta6_installer.exe. There is no Grand Theft Auto VI demo.

That last line is the whole test. Rockstar Games has announced no demo, no beta and no early access, which makes the word demo inside a domain name proof of the fake by itself. Take-Two’s pre-order announcement of June 24, 2026 names four sales channels and no others: the PlayStation Store, the Microsoft Store, the Rockstar Games Store, and global retailers and storefronts, for the two editions of the game.

File size is the second tell. gta6_installer.exe weighs 1.1 megabytes, a figure with no relation to installing a game of this scale, and Malwarebytes published its SHA-256 hash, which opens a8f19d59. The fake was spotted on August 19, 2026, the day after stolen gameplay videos first went online.

The opposite extreme is circulating too. Tom’s Hardware described a fake ISO of roughly 113 GB, padded with more than 99.99 percent zeroes around a payload of about 50 KB, the filler existing only to make the size believable. And no PC version has been announced to date, so an install file you download cannot have come from Rockstar.

Visit Leonida postcard for Ambrosia, refinery at dusk with a stars and stripes storage tank
The official Ambrosia postcard, published by Rockstar with the screenshot set. © Rockstar Games. Official asset used for editorial illustration.

What arrives is Vidar, a credential stealer sold on subscription. Malwarebytes counts 19 browsers on its target list, Chrome, Edge, Firefox, Brave, Opera and Vivaldi among them. It reads Thunderbird profiles, goes after the WebView2 browser inside Roblox Studio, and launches legitimate browsers in headless mode so that saved passwords are read out by a process the machine already trusts. Session cookies and browsing history leave with them.

Deleting the file does not close the door. Malwarebytes puts it in one line:

An infostealer doesn’t need to remain on your computer to cause lasting damage

A stolen session cookie opens an account without ever asking for a password, which is why changing credentials and signing out of every active session still matters once the executable is gone.

The August 24 analysis leaves two gaps. No victim count has been published for this campaign, and nobody has established who hosts or operates the four domains. The other markers of a fake, from the impostor account to the word confirmed used with no official source behind it, are gathered in our guide to spotting a fake GTA 6 leak.

Read next