Indicators are what attackers leave behind. Stolen credentials are what they arrive with.
TLP:WHITE39 IOCs
Gamers Get Played: Fake GTA6 Leaks Deliver a Grab Bag of Malware
Threat Actors
Malware Families
Diamond Model
Adversary(34)
Infrastructure(1)
Capability(42)
Victim
Indicators of Compromise
Indicators of Compromise39
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| SHA256 | 43ed19c70200580f95cd31098df1217ce0305adc83e7950f00a48e9451f9192e file-hashintel-blogloader | Medium | 53 | Oct 9, 26 |
| CVE | CVE-2023-1389 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| CVE | CVE-2025-49704 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| CVE | CVE-2022-30190 exploitintel-blogloader | High | 77 | Jun 12, 26 |
| CVE | CVE-2025-0994 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| CVE | CVE-2022-47986 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| SHA256 | a8c60f952c9d7a73652877074ac4aba940e414c1518a4b1406d8ccf836d24964 file-hashintel-blogloader | Medium | 53 | Oct 9, 26 |
| SHA256 | aa2075698965c994c60203ab8b2f99f77c01add721a60258f3d2fa20a4787ac7 file-hashintel-blogloader | Medium | 53 | Oct 9, 26 |
| CVE | CVE-2025-55182 aptespionageexploit | High | 80 | Jun 2, 26 |
| CVE | CVE-2021-3493 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| CVE | CVE-2023-34362 aptespionageexploit | High | 78 | Sep 3, 26 |
| CVE | CVE-2025-3248 botnetddosexploit | High | 79 | Jun 29, 26 |
| CVE | CVE-2025-53770 exploitintel-blogloader | High | 79 | Jun 12, 26 |
| CVE | CVE-2022-31199 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| CVE | CVE-2021-21974 exploitintel-blogloader | High | 81 | Oct 9, 26 |
| SHA256 | b82c7f077bcc4ee0714ebe35c5467790897b1f6f02283888ad5f0af07d4ba1ed file-hashintel-blogloader | Medium | 53 | Oct 9, 26 |
| CVE | CVE-2022-21894 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| SHA256 | dc74dd29df38d259a4bbd0c60c0717a74ee8c35f5b1339d52c67fff5f8a5348f file-hashintel-blogloader | Medium | 53 | Oct 9, 26 |
| SHA256 | 3ff31781fee2a0ae1e7187b4fe60b80f218d06d1434771c190f08442d3e60bc1 file-hashintel-blogloader | Medium | 53 | Oct 9, 26 |
| SHA256 | e84826ff4599afa4767ebfa4eec90df0e1a0da991961d28bf23afe2ff19c1c5c file-hashintel-blogloader | Medium | 53 | Oct 9, 26 |
| CVE | CVE-2025-49706 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| SHA256 | f2a06bbfcfa3a06b9016c1f43c02b8d1f9216ef80fd29d99a519e03b4a444b92 file-hashintel-blogloader | Medium | 53 | Oct 9, 26 |
| CVE | CVE-2023-46604 exploitintel-blogloader | High | 78 | Aug 27, 26 |
| CVE | CVE-2021-4034 exploitintel-blogloader | High | 78 | Jun 2, 26 |
| CVE | CVE-2022-26134 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| CVE | CVE-2023-2868 exploitintel-blogloader | High | 77 | Jun 2, 26 |
| CVE | CVE-2024-3400 aptespionageexploit | High | 79 | Jun 2, 26 |
| CVE | CVE-2023-22518 aptespionageexploit | High | 81 | Oct 9, 26 |
| CVE | CVE-2024-21412 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| CVE | CVE-2021-33044 exploitintel-blogloader | High | 78 | Jul 30, 26 |
| CVE | CVE-2026-21509 aptespionageexploit | High | 79 | Jun 2, 26 |
| Domain | a0700877.xsph.ru aptespionageintel-blog | High | 58 | Oct 9, 26 |
| CVE | CVE-2017-7921 exploitintel-blogloader | High | 77 | Jun 3, 26 |
| SHA256 | 118ef74ca62cd5a122154bf3eb14e0d2b16a685a7c7aaede85e62b10096222cf file-hashintel-blogloader | Medium | 53 | Oct 9, 26 |
| CVE | CVE-2024-7344 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| CVE | CVE-2023-36025 exploitintel-blogloader | High | 77 | Oct 9, 26 |
| CVE | CVE-2025-53771 exploitintel-blogloader | High | 81 | Oct 9, 26 |
| CVE | CVE-2024-40766 exploitintel-blogloader | High | 79 | Sep 9, 26 |
| CVE | CVE-2025-21042 exploitintel-blogloader | High | 77 | Oct 9, 26 |
IOC Relationship Graph
IOC Relationship Graph39 total IOCs
SHA256CVEDomain