Cybercriminals are exploiting demand for Grand Theft Auto VI with fraudulent websites that promise “VIP Early Access,” beta keys, and subscriptions while impersonating official branding with GTA 6 logos, Vice City imagery, and other convincing artwork. Researchers cited by Malwarebytes and NordVPN reported a surge in these sites, which primarily target PC and Android users by advertising nonexistent versions of the game even though Rockstar Games has announced launch plans for PlayStation 5 and Xbox Series X/S and said there is no public beta program.
Victims are typically asked to send about $250 in cryptocurrency, including Bitcoin, Ethereum, or USDT, but receive neither access nor a legitimate game copy. Instead, the lures can lead to malware infections involving information stealers, banking trojans, adware, or ransomware, extending a pattern seen in earlier GTA 6-themed scams that used fake ads and bogus PC beta downloads to compromise users.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Rockstar Games stated that no public beta program exists and warned users not to trust offers claiming to provide the game before its official release. The warning directly contradicted the fake early-access and beta offers used in the scam campaign.
Malwarebytes and NordVPN identified a significant surge of fraudulent websites impersonating GTA 6 branding and offering fake "VIP Early Access," beta keys, or subscriptions. The sites targeted especially PC and Android users with promises of nonexistent versions of the game.
A similar GTA VI-themed scam was reported in 2024, with fake Facebook ads using leaked gameplay footage to lure users into downloading bogus GTA VI PC beta files. Hackread said this earlier campaign was researched by Bitdefender.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.