A purported GTA VI leaker operating as CyberLeek released alleged gameplay, map material, and apparent story spoilers while promoting the Solana token $CYBERLEEK. Rockstar Games said the game remains unfinished and urged audiences to await its intended November 19 release; Take-Two is pursuing court orders targeting Microsoft, Discord, and X to identify the leaker and stop further disclosures. The token reportedly fell 40% despite additional claimed leaks.
Threat actors exploited interest in the leaks by distributing fake playable GTA VI builds through torrents, Telegram channels, and websites including cyberleek[.]click and cyberleek[.]info. The installers deployed legitimate ConnectWise ScreenConnect clients configured for unattended access through attacker-controlled relays, while lure sites fingerprinted visitors and sent collected data to operators via Telegram Bot API callbacks. A fake DocuSign site, docsn[.]cc, used the same profiling, Telegram reporting, and ScreenConnect delivery pattern, indicating a shared playbook but not confirmed common infrastructure or attribution.

Pull IOCs and campaign context straight into your stack.
12 events from the most recent confirmed update back to the earliest known activity.
The $CYBERLEEK token reportedly reached a market-capitalization peak of $25 million following the leak activity.
The Stop Killing Games consumer campaign publicly distanced itself from CyberLeek's leak tactics, despite CyberLeek framing its manifesto around consumer-rights demands.
The Cyberleek operation began circulating purported GTA VI gameplay footage and map assets while promoting the $CYBERLEEK Solana token. The token's reported market capitalization rose from about $40,000 to more than $2 million after the footage was published.
A Rockstar breach occurred in September 2022 and was attributed in the source material to Lapsus$ member Arion Kurtaj. The later Cyberleek activity was distinguished from this prior incident.
The docsn[.]cc fake DocuSign site used visitor profiling and Telegram reporting similar to the Cyberleek lures, and delivered a separate ScreenConnect MSI client. The infrastructure, relay hosts, ScreenConnect instance, and Telegram bot token differed, indicating shared tactics rather than confirmed shared infrastructure or attribution.
Take-Two sought court orders involving Microsoft, Discord, and X to identify CyberLeek and prevent further disclosures of purported GTA VI material.
Rockstar Games stated that GTA VI was not complete, warned that spoilers could harm the player experience, and urged audiences to wait for the intended release experience.
CyberLeek released material described as the first genuine GTA VI story spoiler, after earlier alleged leaks had focused on open-world gameplay. CyberLeek claimed the leaked build was recent but that the game remained far from complete.
The cyberleek[.]click and cyberleek[.]info lure sites collected visitor IP, geolocation, browser, screen, referrer, and timestamp data, then sent visitor events through the Telegram Bot API. The ScreenConnect client associated with cyberleek[.]click used instance ID e934a059a3e150c6 and connected to gg.noktaarts[.]com.
Threat actors distributed purported playable Cyberleek GTA VI builds through websites, torrents, fake ISO files, and Telegram channels. The malicious MSI installers silently deployed signed ConnectWise ScreenConnect clients configured for unattended attacker access; reports also indicated infostealer delivery.
Rockstar Games and Take-Two submitted requests to remove the circulating purported GTA VI material.
On-chain reporting indicated that the wallet behind $CYBERLEEK exited for an estimated $250,000 across four transactions, largely from accumulated liquidity-provider fees. The proceeds were moved to newly created wallets, with reported transfers to KuCoin and CCE.Cash; no further gameplay leaks were posted after the cash-out.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcexakep.ru
Open sourceintelinsights.substack.com
Open sourcesocradar.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.