Behind the Leak
ID: ab95fb1d-cd02-577c-83b7-261035dfc419
STIX ID: report--ab95fb1d-cd02-577c-83b7-261035dfc419
Feed Name: IntelInsights (Substack)
This report documents how threat actors repackaged GTA VI ‘Cyberleek’ leak hype to distribute malware: lure sites and torrent/Telegram channels profiled visitors (ipify/ipapi), pushed data to Telegram bots, and silently installed signed ScreenConnect clients configured to attacker-controlled relays (confirmed by ScreenConnect instance IDs and sandbox runs) to deliver infostealers and remote access capability, with additional pivots revealing similar playbooks across separate lure themes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
