Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake GTA 6 Demo Distributes Vidar Malware, Harvesting Passwords and Browser Sessions

A counterfeit GTA 6 demo hosted on spoofed Rockstar sites is delivering Vidar malware that steals passwords, cookies and active browser sessions. The campaign highlights why SOC 2 access‑control and security‑awareness controls are essential for audit readiness.

LiveThreat™ Intelligence · 📅 August 28, 2026· 📰 techrepublic.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
techrepublic.com

Fake GTA 6 Demo Distributes Vidar Malware, Harvesting Passwords and Browser Sessions

What Happened — Malicious actors are publishing a bogus “GTA 6 demo” on look‑alike Rockstar webpages. The download bundles Vidar malware, which silently steals saved passwords, browser cookies and active session tokens.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies the type of credential‑theft attack SOC 2 CC 6.2 (Logical Access) is designed to prevent and evidence.
  • Demonstrates the need for documented security‑awareness training that can prove employees can recognize and avoid social‑engineering lures.

Who Is Affected – Gaming enthusiasts, general consumers, and any organization whose employees might click the lure from corporate devices (Technology / SaaS, Retail, Media).

Recommended Actions –

  • Map the incident to SOC 2 CC 6.2 controls and verify that access‑control policies require multi‑factor authentication for privileged accounts.
  • Update your security‑awareness curriculum with a module on fake‑software scams and credential‑theft malware.
  • Deploy endpoint detection that flags Vidar‑related processes and monitors for anomalous cookie extraction.

Source: TechRepublic – Fake GTA 6 Demo Spreads Malware

Technical Notes – Vidar is a modular information‑stealer that injects into browsers to exfiltrate cookies and session tokens; it also scrapes saved passwords from browsers and password managers. Distribution is via social‑engineering (phishing) and malicious download links, not a disclosed software vulnerability.

📰 Original Source
https://www.techrepublic.com/article/news-fake-gta-6-demo-malware-scam/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →