· via TechCrunch
Fake GTA VI demo downloads are info-stealing malware, Malwarebytes finds
Fraudulent Rockstar websites are offering a GTA VI demo that does not exist, delivering an information stealer that harvests browser passwords, cookies and login sessions.

Fake websites promising early access to Grand Theft Auto VI are serving malware instead of a game, according to TechCrunch. The sites impersonate Rockstar Games and advertise a playable demo of the long-awaited title — even though no official demo exists — and visitors who hit the download button receive a file that looks like a game installer but is actually an information-stealing program, as identified by cybersecurity firm Malwarebytes.
How the campaign works
The scheme leans on sheer anticipation. Grand Theft Auto V launched more than a decade ago and went on to sell more copies than any game in history apart from Minecraft, and its sequel has slipped through multiple delays. According to TechCrunch, GTA VI is now expected on November 19, 2026, leaving fans hungry for any scrap of news or playable content.
Attackers have set up counterfeit Rockstar websites that advertise a playable GTA VI demo behind a "Play Now" prompt. Since Rockstar has never released a demo, TechCrunch notes there is no genuine version of this offer that a cautious fan might be missing — any such download is fraudulent by definition.
What the malware takes
Malwarebytes classifies the payload as an information stealer. Once it runs, it searches the victim's web browser for saved passwords, cookies and logged-in sessions.
The session data is the most valuable part of the haul. A stolen session cookie can let an attacker resume a logged-in state as though they were the account owner, without ever needing the password. TechCrunch reports that in some cases this works even against accounts protected by multi-factor authentication, because the attacker is reusing an already-authenticated session rather than logging in from scratch.
The potential damage reaches beyond gaming. Browsers routinely hold sessions for email, social media, banking and workplace tools, so one successful infection can expose a wide slice of a victim's online life.
A hype cycle built for abuse
The timing is deliberate. TechCrunch reports that Netflix will air an extended look at the game on the coming Thursday, an event that could help clarify which of the many circulating leaks are genuine. Stretches like this — a starved fanbase combined with a major media moment — are precisely when searches for demos, betas and leaks spike, giving fraudulent pages their best chance to spread through search results and social platforms.
Why it matters
The incident is a clean example of social engineering that requires no exploit at all: a convincing story plus an impatient victim is enough. It also underlines a real limit of multi-factor authentication. As TechCrunch notes, session theft can in some cases put an attacker inside an account without triggering a fresh login, so MFA alone does not neutralize this class of malware.
The defense is unglamorous. Download software only from sources you can verify, treat any unannounced "exclusive" demo or leak with suspicion, and consider whether the convenience of browser-saved passwords and sessions is worth the exposure. TechCrunch's closing advice generalizes well beyond gaming: do not download something unless you are confident where it came from.
- #malware
- #security
- #gaming
- #phishing
- #info-stealer