Fake GTA 6 Extended Look and demo sites deliver an infostealer
ID: f37cae42-43a7-5e4a-80a1-6cfbc406f4e6
STIX ID: report--f37cae42-43a7-5e4a-80a1-6cfbc406f4e6
Feed Name: Security Boulevard
Malicious actors set up convincing fake GTA 6 demo sites that distribute a 1.1 MB executable (gta6_installer.exe) identified as a Vidar infostealer; the malware steals saved passwords, session cookies, browser profile data and FTP credentials by launching legitimate browsers in headless mode and retrieving configuration via attacker-controlled profiles (dead-drop resolvers). The report provides IOCs (domains, SHA-256 hash, resolver URLs, network hosts), technical details of extraction and delivery, and guidance for detection, remediation, and account recovery.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
