logo

Vidar Uses Victims’ Own Browsers to Extract Data Protected by Browser Encryption

ID: 4513754f-4250-555f-9c8a-7e8e2cf58538

STIX ID: report--4513754f-4250-555f-9c8a-7e8e2cf58538

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Varshini

...
...

Cybercriminals are exploiting GTA 6 hype by hosting fake Rockstar demo websites that distribute a 1.1 MB executable which is the Vidar infostealer; the malware harvests saved passwords, cookies, session tokens, browsing history and other profile data from many browsers by launching legitimate browser processes in headless mode to bypass browser encryption. The report includes distribution domains (e.g., gta6demo.asia, gta6demo.eu) and explains the attack vector and impact of short-lived infostealer execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.