< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

GTA 6 anticipation exploited by malware and crypto-drainer scams

Cybercriminals are utilizing the anticipation for Grand Theft Auto VI (GTA 6) to deploy various malware and phishing schemes. These attacks target fans through fake websites offering leaked copies, early access, or PC demos.

One method involves fraudulent countdown sites that use accurate Rockstar Games information to appear legitimate. These sites host wallet drainers designed to steal cryptocurrency and other assets from connected blockchain wallets. Other sites distribute the Vidar infostealer via malicious files such as ‘gta6installer.exe’.

The Vidar malware targets sensitive data from 19 different browsers, including Google Chrome, Mozilla Firefox, and Microsoft Edge. It collects passwords, cookies, and session data, allowing attackers to bypass two-factor authentication by hijacking active sessions. The malware also specifically searches for and empties digital cryptocurrency wallets. Because the infection often runs in the background without visible windows, it can go unnoticed by users.

Entities

Grand Theft Auto VI · Malwarebytes · Rockstar Games · Vidar Infostealer