How a "Spotless" FiveM Cheat Was Spying on 600+ Users — and Took a Picture of Us While We Analyzed It
Click to enlarge
23 בספטמבר 2026
12 min read
ZeroTrust Team

How a "Spotless" FiveM Cheat Was Spying on 600+ Users — and Took a Picture of Us While We Analyzed It

Spotless sold itself as an undetectable FiveM cheat. Under the hood it was spyware: silent desktop screenshots, Discord identity theft, forced BSODs, and a remote command channel across 601 accounts. Cloudflare already took down the payload links. Discord, Stripe, and authorities have the report.

A few days ago we dug into a paid FiveM and Fortnite cheat called Spotless. The pitch was simple: undetectable external, aimbot, ESP, HWID spoofing. Tagline: "Stay undetected, stay spotless." They also sell Spotless Spoofer.

VirusTotal said 0 detections. That does not mean clean. It means the file on disk is packed so scanners cannot read it.

What we found in memory was not "just a cheat." It was spyware.

  • It had 601 users in the live C2 database.
  • It reads Discord ID, username, and email from a local cache file.
  • It takes full desktop screenshots with no Windows privacy prompt.
  • Its C2 JSON includes a `command` field — remote tasking, like RCON on a home PC.
  • It can Blue Screen the machine if it sees analysis tools.

While we dumped Spotify.exe to inspect it, the anti-tamper fired. It photographed our desktop and tried to upload that frame to the developer's Discord. No flicker. No toast. No consent.

A lot of buyers are kids, often on a family PC. Spotless does not care who is logged in. Screenshot + Discord scrape = whoever uses that machine. Fill in `command`, and a stranger can push work to that box.

Silent screen capture and remote control without consent is malware behavior — the kind computer-crime laws target. We are researchers, not a court. Here is what the binary does, and what we did about it.

We reported it to Discord Trust & Safety (investigating), Stripe, Cloudflare (R2 links already restricted), the C2 host, game platforms, and authorities. Victim identifiers are redacted below.

Most vendors would ship a detection and stop. We went after the source — loader, C2, R2 hosts, Discord guild, payments — because hashes do nothing against an in-memory SP7L pack.

Quick summary

  • Silent screenshots via signed `Spotify.exe`
  • Discord identity from unencrypted `scope_v3.json`
  • Per-user `Suspect …` webhook when you poke it
  • C2 fields `command` + `webhookUrl` (remote control / exfil routing)
  • Forced BSOD on inspect (`RtlAdjustPrivilege` + `NtRaiseHardError`)
  • 601 registered users at dump time

1. Injection: OBS launches Spotify

Buyer instructions:

  1. Open Notepad
  2. Run OBS Studio as Administrator
  3. Wait for the ImGui cheat menu

Process tree during a live run:

obs64.exe (PID 9228)  --->  Spotify.exe (PID 2144)

Everything under `%APPDATA%\Spotify` was real Spotify AB–signed code. No shady DLL on disk. The cheat injects into Spotify's memory after OBS starts it.

To hide the overlay from captures it calls:

SetWindowDisplayAffinity(hwnd, WDA_EXCLUDEFROMCAPTURE); // 0x00000011

You can see the menu on the monitor. OBS, Discord screen share, and anticheat grabbers see a clean desktop.

2. Custom packer: SP7L (why VT is 0/70)

Payload `fe45698beaa2237e` (~4.7 MB) came from the seller's Cloudflare R2 bucket. It is not a normal PE. Hex header:

0000:  53 50 37 4C 01 01 00 00  94 A0 AE 4A F5 B1 90 EC  [SP7L...........J....]

SP7L       = Spotless Loader magic
01 01 00 00 = version 1.1
next 8 bytes = IV / salt

SHA256: d66c841e43a08223982d5f110b43b48ecbb35b131638e425fc5972bb1e1574a3

No `MZ` on disk → static AV often fails. Decryption happens in Spotify's process.

3. What we pulled from the 1.07 GB dump

Disk looked clean, so we dumped live memory: Task Manager → Spotify.exe (PID 2144) → Create memory dump → `Spotify.DMP` (1.07 GB).

From RAM:

  • C2: `popadas.com:5000` → `2.26.145.65` (Hydra-Shield, Paris)
  • User-Agent: `Loader-Protected/1.0`
  • App ID: `6907713df3e42f6e0026d777`
  • Users: `totalUsers: 601`
  • Remote control: JSON fields `command` and `webhookUrl`
  • Exfil marker: `------SuspectScreenshotBoundary` (235 hits)
  • Images: hundreds of PNG headers in memory, including a 2560×1440 desktop frame staged for upload (same image buffered 3× during the multipart POST)

Auth body clients send (redacted):

{
  "appid": "6907713df3e42f6e0026d777",
  "discordId": "[REDACTED_DISCORD_ID]",
  "hwid": "[REDACTED_SID]",
  "version": "0.1"
}

C2 heartbeat from the dump (redacted):

{
  "timestamp": 1790157671573,
  "sessionid": "[REDACTED]",
  "command": null,
  "webhookUrl": null,
  "user": {
    "username": "[REDACTED_USER_ID]",
    "hwid": "[REDACTED_SID]",
    "ip": "[REDACTED_IP]",
    "lastlogin": 1790157099,
    "createdate": 1788833441,
    "expiry": 1791425441
  },
  "app": {
    "name": "Public-Bypass",
    "version": "0.1",
    "totalUsers": 601,
    "onlineUsers": 0
  },
  "expiry": 1791425441,
  "hasAccess": true,
  "expiresIn": 1267770
}

`command: null` still matters

In our session those fields were empty — the seller was not actively tasking this box. The API still supports it. Same channel that checks a license can later push remote work or point screenshots at a new webhook. That is RCON on a home PC, sold as ESP.

Module downloads (Cloudflare R2):

  • `https://pub-43be6e29d8d14305be8e3747ab1cbb56.r2.dev/fe45698beaa2237e` — FiveM External
  • `https://pub-43be6e29d8d14305be8e3747ab1cbb56.r2.dev/7fd18ddb8f8f5113` — Spotless Spoofer

4. Anti-tamper: it photographed us

We carved PNGs out of the dump and got the loader's own surveillance frames — our analysis desktop, still sitting in Spotify RAM.

Desktop screenshot recovered from Spotify.exe memory dump — Task Manager about to create memory dump of PID 2144
Click to enlarge

From Spotify.exe RAM: Task Manager on PID 2144, cursor on "Create memory dump file" — when the trap fired.

Another staged frame from the same dump: PowerShell ISE parent-process audit (obs64.exe → Spotify.exe), Task Manager, VirusTotal still at 0 detections. Usernames redacted.
Click to enlarge

Another staged frame from the same dump: PowerShell ISE parent-process audit (obs64.exe → Spotify.exe), Task Manager, VirusTotal still at 0 detections. Usernames redacted.

In the frames:

  • Task Manager → right-click Spotify.exe → Create memory dump file
  • PowerShell ISE auditing modules; parent = `obs64.exe`
  • Chrome on VirusTotal at 0 detections
  • Clock ~8:13–8:15 PM

How the screenshot happened with no warning

  • No flicker / dimming (not Snipping Tool)
  • No Windows "recording" indicator — call came from signed Spotify.exe
  • No sound or permission popup

Frame → multipart body with `------SuspectScreenshotBoundary` → Discord webhook.

Trigger chain

Blacklist in memory includes Task Manager, Process Hacker, Wireshark, API Monitor, x64dbg-class tools, plus ThreatLocker and Symantec Endpoint Protection.

If it decides you are inspecting it, it can also BSOD the PC via `RtlAdjustPrivilege` + `NtRaiseHardError`.

When it saw Task Manager + PowerShell on PID 2144:

trying url=https://popadas.com/api/ep/protect-detected

Then:

  1. C2 hits Discord bot `1547636494796328970`
  2. Channel `[REDACTED_CHANNEL_ID]` created 20:59:08 GMT (16 Sep 2026)
  3. Webhook `[REDACTED_WEBHOOK_ID]` created 20:59:09 GMT (1 second later), named `Suspect [REDACTED_USER_ID]`
  4. Desktop upload so the seller sees your tools

We dumped memory mid-upload, so the frame was still in RAM.

5. Discord scrape: scope_v3.json

Plaintext in the dump:

[REDACTED_DISCORD_ID]:[REDACTED_USERNAME]:[REDACTED_EMAIL]
C:\Users\[REDACTED]\AppData\Roaming\discord\sentry\scope_v3.json

Discord's Sentry crash SDK caches session context in unencrypted JSON:

  • Discord snowflake ID
  • Username
  • Email

Tokens use DPAPI. This file does not. Any user-mode process can read it in milliseconds.

On a shared family login, that can be a parent's Discord — tied to a cheat buy they never made.

6. Why scrape Discord cache?

Three reasons (they stack)

1. Easy login — UI says "Sign in with your Discord ID — No password". Loader reads the ID from disk instead of making buyers copy a snowflake. 2. Anti-alt / license bind — Links a burner Discord to the real desktop account + Windows SID (chargebacks / key sharing). 3. Deanonymize analysts — Trip anti-tamper → email, username, and screenshots go to the seller.

7. Infra, reports, and the takedown

C2 / network

  • `popadas.com` → `http://2.26.145.65:5000` (Hydra-Shield AS214560, Paris — `[email protected]`)
  • UA: `Loader-Protected/1.0`
  • App ID: `6907713df3e42f6e0026d777`

Payloads (R2)

  • `https://pub-43be6e29d8d14305be8e3747ab1cbb56.r2.dev/fe45698beaa2237e`
  • `https://pub-43be6e29d8d14305be8e3747ab1cbb56.r2.dev/7fd18ddb8f8f5113`

Discord (TA)

  • Guild `1547634764905979954`
  • Bot `1547636494796328970`
  • Webhook `Suspect [REDACTED_USER_ID]` (`[REDACTED_WEBHOOK_ID]`, token redacted)

Who we told

  • Discord Trust & Safety — investigating
  • Stripe — payment processing for malware sales
  • Cloudflare — domain + R2 (URLs already restricted)
  • Hydra-Shield — C2 IP abuse
  • Epic / Cfx.re — capture-exclusion + OBS→Spotify flow
  • Authorities — full evidence package

Cloudflare: links restricted

Cloudflare Trust & Safety confirmed they restricted access to the reported R2 URLs (Spotless FiveM + Spoofer). Public `*.r2.dev` downloads for those objects are dead. Expect new buckets later.
Cloudflare Trust & Safety email confirming restricted access to reported Spotless R2 URLs
Click to enlarge

Cloudflare (23 Sep 2026): "We have restricted access to the reported URL(s)."

Hours later, Spotless Discord lit up: cheat loads then unloads, inject fails, "host has to be down."

Spotless Discord customers reporting the cheat loads then unloads
Click to enlarge

Buyers: load → unload, asking staff for a fix.

Spotless Discord customers speculating the host is down
Click to enlarge

"There host has to be down" / first outage with no announcement.

Spotless Discord customer posting Fatal Error ntdll.dll when trying to inject the menu
Click to enlarge

Inject broken: Fatal Error in ntdll.dll.

Staff blamed "domain provider instability" and told people to VPN before inject (even dropped a ProtonVPN link). Classic workaround when Cloudflare cuts distribution — no mention of the abuse report.

Spotless staff admitting domain provider instability and telling users to inject over VPN
Click to enlarge

Staff: VPN before inject until "everything stabilizes."

8. What to look for (IOCs)

Do not rely on Spotify.exe hashes.

  • Process tree: `obs64.exe` → `Spotify.exe` (weird parent)
  • Window title: `Spotless Loader`
  • HTTP to `popadas.com` / `2.26.145.65:5000`, UA `Loader-Protected/1.0`
  • Downloads from that R2 pub bucket (or a rotated one)
  • Multipart body containing `SuspectScreenshotBoundary`
  • Files starting with ASCII `SP7L` instead of `MZ`
  • BSOD when staff open Process Hacker / Wireshark mid-check → treat as anti-analysis

ZeroTrust Forensic Scanner is built for this class: in-memory loaders, signed-process abuse, leftover execution artifacts.

Takeaway

"0 detections" is not a clean bill of health. Spotless hid as a non-PE pack, lived inside Spotify, and sold spyware as an aimbot.

601 people installed silent screenshots, Discord identity theft, crash-on-inspect, and a remote `command` channel. On a kid's family PC, that is a stranger with eyes on the household desktop.

We did not stop at a detection signature. We went after the source — dump, SP7L, C2, R2, Discord, Stripe, host abuse, law enforcement.

Cloudflare already killed the payload URLs. Discord is investigating. Stripe has the payment trail. Authorities have the package.

If you run a server: treat Spotless as malware. If you bought it: uninstall, rotate Discord, assume your screen may have been photographed — and stop handing strangers RCON to your home PC for ESP.

Protect your community

ZeroTrust detects in-game cheats and hunts the loaders behind them when they turn into spyware. Explore ZeroTrust · Discord — Forensic Scanner included.