All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
A fake Grand Theft Auto VI demo is circulating online, but anyone who runs it could hand criminals access to far more than their gaming account.
Researchers at Malwarebytes uncovered a network of websites impersonating Rockstar Games and advertising an “official” GTA 6 download. Instead of a playable demo, their download buttons deliver an information-stealing malware program that can collect passwords, browser cookies, and active login sessions.[1]
Those stolen sessions could allow attackers to access accounts without entering the victim’s password or completing a new two-factor authentication check. That means changing your passwords may not be enough to lock them out.
What the fake demo steals
How stolen sessions can bypass your password
What to do if you ran the fake installer
How to avoid fake game downloads
Bottom line
There is no official GTA 6 demo (yet)
Fraudulent websites capitalize on intense interest in leaked GTA 6 material and Rockstar’s upcoming extended preview of the game.
Some appeared in Google results for GTA 6 demo searches and copied Rockstar’s artwork and promotional language. According to Malwarebytes, their “Play Now” buttons downloaded a file named gta6_installer.exe.
However, Rockstar has not released or announced a playable GTA 6 demo, beta, PC build, or early-access version.
The company’s official GTA 6 website says its “Extended Look” will premiere on August 27. That is a video presentation, not a downloadable game. GTA 6 itself is scheduled for release on November 19, 2026, for PlayStation 5 and Xbox Series X|S.
The supposed installer offers another clear warning sign: It is only 1.1 MB. That is nowhere near large enough to contain a modern blockbuster game.
What the fake demo steals
The malicious installer contains Vidar, an established family of information-stealing malware.
Once opened, it can quietly search a computer for:
- Saved passwords and login information
- Browser session cookies
- Browsing and download histories
- Autofill information and other browser profile data
- Credentials saved by FTP clients
Researchers observed the malware targeting 19 browsers, including Chrome, Edge, Firefox, Brave, Opera, and Vivaldi. It also searched Thunderbird profiles, Perplexity’s Comet browser, and the browser component built into Roblox Studio.
The malware does not display a game, installation window, or obvious error message. To the victim, the fake installer may simply appear to do nothing.
Malwarebytes did not find a mechanism that would automatically restart the malware after the computer rebooted. However, the program does not need to remain installed to keep causing damage. Once criminals steal account credentials and session tokens, they can keep trying to use them.
How stolen sessions can bypass your password
Websites use session cookies or tokens to remember that you have already signed in. They're why you don't need to re-enter your password every time you open another page.
If a criminal steals a valid session token, they may be able to reuse that authenticated session and enter the corresponding account without signing in normally.
This can also weaken the protection offered by two-factor authentication. Two-factor authentication helps verify a new login, but a stolen session was created after the legitimate user had already passed that check. Depending on the website’s security controls, the attacker may not be asked for either the password or a second authentication factor.
The malware uses legitimate Chrome, Edge, and Firefox programs installed on the computer to access protected browser information. It launches the browsers in a hidden mode and directs them to temporary profile folders, according to Malwarebytes.
Rather than visibly breaking the browser’s encryption, the malware works through software that is already trusted to read browser data.
As Cyber Security News notes, the resulting exposure can extend to email, social media, shopping, payment, and gaming accounts.
What to do if you ran the fake installer
If you downloaded and opened a supposed GTA 6 demo, assume that passwords and browser sessions stored on that computer may have been compromised.
Take these steps:
- Scan the affected computer. Use a trusted antivirus or malware-removal program and remove anything it detects.
- Switch to a clean device. Do not use the potentially infected computer to secure your accounts until you have scanned and cleaned it.
- Change your most important passwords. Start with your primary email account, then move to banking, payment, social media, shopping, and identity-related accounts. Use a unique password for each account.
- Sign out everywhere. Look for settings labeled “sign out of all devices,” “active sessions,” “manage devices,” or similar language. Revoking active sessions can invalidate stolen cookies and tokens.
- Remove unfamiliar access. Check for unknown devices, authorized applications, recovery email addresses, phone numbers, and email forwarding rules.
- Enable two-factor authentication. It may not stop the reuse of a session that was already stolen, but it can help protect future login attempts after you revoke existing sessions.
- Monitor your accounts. Watch for unfamiliar purchases, messages, password-reset requests, login alerts, or changes to account settings over the following weeks.
Do not overlook gaming accounts such as Steam or Epic Games. They may contain saved payment methods, digital inventories, personal information, and access to other connected services.
How to avoid fake game downloads
Download games, demos, and updates only from the publisher’s official website or established stores such as Steam, the Epic Games Store, the PlayStation Store, and the Microsoft Store.
A polished website is not proof that a download is legitimate. Criminals can easily copy official artwork, logos, screenshots, and announcements. Malicious websites can also appear in search results or paid advertisements.
Treat supposed leaks, private betas, and early PC builds with particular suspicion. If a publisher has not announced a download through its official channels, clicking “Play Now” could give someone else early access to your accounts instead.
Bottom line
Unfortunately, no legitimate GTA 6 demo or PC installer is available. Gamers will have to wait another couple of days for anything new from Rockstar Games, and websites claiming otherwise may be distributing malware that steals passwords and active browser sessions.
If you ran one of these installers, removing the malware is only the first step. Change important passwords from a clean device, revoke every active session, remove unfamiliar devices, and continue monitoring your accounts for unauthorized activity.