Modified FiveM Spoofer Targeting Gamers
ID: 1831eae8-4ac0-5ec3-802a-71f39fbeb463
STIX ID: report--1831eae8-4ac0-5ec3-802a-71f39fbeb463
Feed Name: Cyble Blog
### Executive Summary: This report describes an active campaign targeting GTA5 FiveM players in which a threat actor advertises a purported 'Cloud Spoofer' via a malicious site, Discord server and YouTube promotions; the distributed RAR contains a modified spoofer executable that installs AsyncRAT and a browser stealer from cloud-spoofer.xyz. The analysis includes behavioral details, file hashes, malicious URLs, MITRE ATT&CK mappings, and recommended mitigations to block distribution and detect exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
