Security1 distinct publisher3 min readPublished
Fake Rockstar pages push a 1.1 MB Vidar sample that takes session cookies as well as saved passwords. Cookies replay past 2FA, which makes this a corporate access problem wearing a consumer costume.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
A session cookie is a bearer token. Whoever holds it is already inside the fence a second factor guards, which is why Malwarebytes' observation that stolen browser sessions can sometimes be reused without the normal login process is the load-bearing line in its writeup [5]. The collection list in this sample puts session cookies alongside saved passwords, browsing history, autofill data and credentials held by FTP clients [8]. For anyone doing cleanup, a password reset covers exactly one item on that list. The cookie outlives it unless something server-side tears the session down.
The costume is consumer. Malwarebytes frames the payoff as access to email, social media, gaming and shopping accounts [20], and the bait is a demo that does not exist [10]. The stealer, though, reads whatever the browser has remembered, across 19 browser targets including Chrome, Edge, Firefox, Brave, Opera and Vivaldi, and it looks at Thunderbird profile directories too [7]. Nothing in that sweep distinguishes a personal webmail session from a work single-sign-on session that happens to live in the same profile. An employer betting this one lands only on gamers is betting on staff maintaining clean separation between browser profiles at home.
The part worth reading as a template is the calendar. The first gta6_installer.exe sample was spotted on August 19, one day after the Cyberleek footage and the apparent Leonida map began circulating [12], and Rockstar's Extended Look premieres on Netflix on August 27 before reaching its YouTube channel later the same day [1]. That is an eight-day window of search volume the operators knew about in advance [18], with the November 19, 2026 console release sitting roughly three months beyond it [19]. Publishers announce media dates early. So the spike is schedulable, and so is the infrastructure built to meet it.
The triage tell here is cheap and worth keeping. The delivered executable is 1.1 MB, and Malwarebytes notes its own screenshot of one of these sites was larger than the file the site was offering [9]. Rockstar has announced no demo and no PC version, and the game is a PS5 and Xbox Series X|S title [10], so any Windows executable presented as GTA 6 fails on its face.
Around it sits an audience already being monetised several ways: leaked clips carrying promotion for a cryptocurrency token associated with Cyberleek, a Cyberleek site soliciting donations and selling advertising placement in future GTA 6 videos, and recycled or AI-generated footage passed off as new leaks [14]. Take-Two's DMCA subpoenas seek records from Microsoft and Discord to identify whoever is behind the leaks [13], which is a different target from whoever is running the stealer network riding the same search terms. Malwarebytes says it detects the sample and blocks the associated sites and infrastructure [17], which is one vendor's coverage of the subset it has found. The demand is durable: earlier this year, scammers were charging hundreds of dollars for fake GTA 6 early access [15], and in 2022 Rockstar confirmed an attacker had stolen and published development footage [16].
Ranked by verification strength, evidence, and original report placement.
Rockstar has announced an extended look at GTA 6 for August 27, premiering on Netflix before appearing on its YouTube channel later that day.
Malwarebytes identified a network of sites appearing in searches for a GTA 6 demo and impersonating Rockstar Games; one Google result advertised an "Official Download".
The sites copy Rockstar's genuine promotion for the August 27 extended look and use "Play Now" links that can lead visitors to download gta6_installer.exe.
The executable delivered is not a demo, game or video but an information stealer designed to take passwords stored in browsers, cookies and authenticated sessions.
Because stolen browser sessions can sometimes be reused without going through the normal login process, even two-factor authentication may not be enough to stop them.
The installer belongs to the Vidar family, a well-established infostealer sold as a service to cybercriminals.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific single-vendor analysis, no publishable indicators
The claims rest on first-hand sample analysis with concrete, checkable specifics: a named malware family, a 1.1 MB file size, 19 enumerated browser targets, Thunderbird profile access, an itemised collection scope, and dated first sighting. That is substantially better than a summary advisory. It is capped, however, by being one vendor's account with no hashes, domains or C2 details in the cluster, no third-party confirmation of the Vidar attribution, and a self-reported detection claim that cannot be verified from the supplied material.
Live campaign, unquantified reach
Real-world activity is observed rather than hypothetical: a network of impersonation sites was live, at least one surfaced in Google results, a sample was captured on August 19, and the surrounding leak drove genuine search demand while Take-Two pursued takedowns and subpoenas. But nothing in the cluster quantifies spread: no telemetry counts, no victim or infection numbers, no number of domains, and no measure of how much search traffic the fake pages captured. Adoption is therefore confirmed-but-small in evidenced terms.
Mechanism accurate, scale asserted rather than shown
The core technical framing is sound and not inflated: session-cookie theft genuinely can bypass a completed 2FA login, and the report itself deflates the lure by pointing out the 1.1 MB file size and the absence of any real demo. The overstatement is one of implied magnitude. A single captured sample and an unspecified 'network of sites' are presented with the weight of a significant campaign, with no infection counts, no domain list and no telemetry, while the vendor's own detection claim closes the narrative. Slightly overstated relative to what is measured, not materially so.
Vendor threat-intel with product tie-in; monetised actors in-frame
The only source is a commercial security vendor writing about a threat its own products claim to detect and block, and the analysis ends on that coverage statement, which is a direct marketing incentive. The subject matter compounds it: the surrounding leak economy is itself monetised through a Cyberleek-linked crypto token, donations, paid ad placements in leak videos, and prior paid fake early-access scams, so multiple parties in the story have financial reasons to amplify GTA 6 leak attention. No countervailing independent publisher is present to dilute this.
Plausible and specific, but uncorroborated
Confidence is limited mainly by source structure rather than by internal weakness. The technical account is internally consistent, dated, and consistent with well-documented infostealer behaviour, and the schedule and legal facts are independently checkable in principle. But the cluster contains exactly one publisher, that publisher is commercially interested, key verification artefacts (hashes, domains, infrastructure) are absent, and campaign scale is unmeasured. That supports moderate, not high, confidence.
product
GTA VI's $79.99, disc-free preorder sets the ceiling everyone else prices against1 distinct publisher
security
GTA VI leak: extortion leverage moves from the regulator to the fanbase1 distinct publisher
build
A DMCA notice over one GitHub repo now asks Microsoft for MachineGuids from three Discord servers1 distinct publisher
product
Cyberleek dumped GTA 6 footage nine days early, with a memecoin attached and no provenance2 distinct publishers
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 24, 2026