- Verification Status: Rockstar Games has not released any official demo or playable build for Grand Theft Auto VI as of August 2026, making all current “demo” downloads fraudulent.
- Malware Impact: Fraudulent installers deliver the Vidar info-stealer, which can bypass two-factor authentication and drain cryptocurrency wallets by stealing browser cookies and session data.
Technical Breakdown of the Vidar Infostealer Scam
Security researchers have confirmed that that fake Grand Theft Auto VI demo is actually a sophisticated trap designed to deploy malicious software. Despite the high level of anticipation for the title, Rockstar Games has not released any official demo, beta, or playable test build as of August 2026. Cybercriminals are currently exploiting this demand by operating fraudulent domains such as gta6demo.eu, gta6demo.us, and rockstar-gta-6.com to impersonate the official developer.
A prominent version of this campaign involves a massive 113GB ISO file. This file size is intended to mimic a modern high-budget game, yet analysis reveals that 99.99% of the file consists of zero-filled padding or junk data. Hidden within this bulk is a tiny 50KB virus. According to reports from PCMag, this scam targets users looking for early access to the game. Once executed, the malicious installer runs PowerShell commands, specifically “Add-MpPreference -ExclusionPath %SystemDrive%\”, which whitelists the entire C: drive in Windows Defender to prevent detection.
Data Exfiltration and System Persistence
The primary malware identified in these campaigns belongs to the Vidar family. This info-stealer is engineered to exfiltrate sensitive data, including saved passwords and browser cookies. By stealing active browser sessions, the malware can bypass two-factor authentication (2FA) for various sensitive accounts. This method of compromise is an evolving threat in the cybersecurity landscape, similar to how ToxicPanda Android malware utilizes system permissions to facilitate fraud. In the case of the GTA VI scam, the software also scans for specific file paths and browser extensions to drain cryptocurrency wallets.
To maintain a presence on the infected machine, the malware creates scheduled tasks that masquerade as legitimate software updates. Researchers have found tasks named “iTunesUpdate” or “SlackUpdate” that ensure the infection remains active. Furthermore, Malwarebytes has observed the use of “ClickFix” loaders. These loaders trick users into manually pasting and running malicious code from their clipboard. The campaign also employs server-side repacking, a technique that changes the file hash for every individual download to evade traditional antivirus blocklists.
Official Timeline and Legal Consequences
The persistence of these scams is fueled by the fact that the actual game is currently only confirmed for console platforms. While users search for PC versions, a Fake GTA 6 Demo remains a primary vector for infection on Windows. Rockstar Games has confirmed that the official release window for Grand Theft Auto VI is Fall 2025 on PlayStation 5 and Xbox Series X/S. There is no verified information regarding a PC release date at this time.
While fans continue to express their excitement, such as during the recent GTA 6 Fan Protests, the legal battle against leakers continues. Take-Two Interactive has recently initiated legal efforts to subpoena Discord for device IDs associated with the “Cyberleek” group, who are believed to be responsible for previous footage leaks. Users are advised to avoid any third-party “playable” leaks to protect their personal data and financial information.



