Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Fake GTA 6 Demo Sites Distribute Credential‑Stealing Infostealer

Scammers impersonating Rockstar Games host bogus GTA 6 demo pages that deliver a 1.1 MB infostealer, harvesting browser passwords and session cookies. The episode highlights the need for robust SOC 2 access‑control and security‑awareness controls to mitigate credential‑compromise risk.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 malwarebytes.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
malwarebytes.com

Fake GTA 6 Demo Sites Distribute Credential‑Stealing Infostealer

What Happened — Cybercriminals set up counterfeit Rockstar‑styled websites that appear in search results for a “GTA 6 demo.” The “Play Now” buttons deliver a 1.1 MB executable (gta6_installer.exe) that installs an information stealer capable of extracting browser passwords, cookies and active sessions, potentially bypassing 2FA.

Why It Matters for Compliance & Audit Readiness —

  • The incident exemplifies a classic credential‑compromise scenario that SOC 2 CC6 (Logical Access) controls are designed to prevent and evidence.
  • Continuous monitoring of phishing‑related alerts and documented security‑awareness training are essential audit evidence of due diligence.
  • Demonstrating a defensible incident‑response workflow for malicious downloads satisfies the SOC 2 CC7 (Incident Management) requirement.

Who Is Affected — Gaming and entertainment companies, streaming platforms, and any organization whose employees or customers might search for high‑profile game releases.

Recommended Actions —

  • Review and tighten web‑filtering rules for known malicious domains.
  • Verify that all users receive regular phishing‑simulation training and that completion records are retained for audit.
  • Ensure password‑manager usage policies and MFA enforcement cover session‑cookie reuse scenarios. Source: Malwarebytes Labs

Technical Notes — The delivered payload is a generic information stealer that harvests stored browser credentials and session cookies; no CVE is involved, but the attack leverages social engineering and trusted‑brand impersonation. Source: same link

📰 Original Source
https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-gta-6-extended-look-and-demo-sites-deliver-an-infostealer ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →