logo

Behind the Leak

ID: ab95fb1d-cd02-577c-83b7-261035dfc419

STIX ID: report--ab95fb1d-cd02-577c-83b7-261035dfc419

Feed Name: IntelInsights (Substack)

Threat Score
70/100

Date Published: 2026-08-26

Date Updated: 2026-08-26

Author: Vasilis Orlof

...
...

This report documents how threat actors repackaged GTA VI ‘Cyberleek’ leak hype to distribute malware: lure sites and torrent/Telegram channels profiled visitors (ipify/ipapi), pushed data to Telegram bots, and silently installed signed ScreenConnect clients configured to attacker-controlled relays (confirmed by ScreenConnect instance IDs and sandbox runs) to deliver infostealers and remote access capability, with additional pivots revealing similar playbooks across separate lure themes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.