An analysis of the evidence surrounding the GnomodelincuenT attribution and the broader Cyberleek operation.
TL;DR
IntCyberDigest claims that Spaniard "GnomodelincuenT" ([email protected]) operates the secondary channel cyberleekario. Our analysis finds the attribution weak, based primarily on a single chain of evidence, and potentially misattributed.
Evidence chain:
Google Drive shared in cyberleekario Telegram
↓
Owned by [email protected]
↓
osint.industries profile picture + name match
This only proves possession of a shared Drive. It does not prove authorship of the original leaks, control of the Cyberleek brand, or operational capability.
Named individual publicly denied it. Handle traces to real Spanish teenage meme persona active ~2012-2013. Stale, heavily breached personal account. Easy to find. Hard to operationally connect to a 2026 leak + memecoin operation.
Cyberleek's own fourth video carries permanent watermark:
CYBERLEEK DOES NOT HAVE TWITTER - OFFICIAL NEWS ONLY HERE
Multiple copycat channels existed. Separate researchers traced the core actor to German/Swiss forum history 2018-2023. Attributing the secondary channel to a Spanish personal Gmail deserves low confidence.
1. What Cyberleek Actually Is
Starting 18 August 2026 an anonymous actor/brand calling itself Cyberleek released multiple clips of apparently genuine unreleased Grand Theft Auto VI gameplay (basketball, highway driving, taser/truck hijack, junkies camp, plane flyover) plus a full Leonida state map. Material wrapped in anti-consumerist manifesto against digital pre-orders and games that die when servers shut down.
Simultaneously launched and pushed Solana memecoin:
Token : $CYBERLEEK
Mint : ApZuxdpzMrbEYTGEzeY9afh5pj9d6qPRJCTgQYiipbKg
Token creation, Raydium pool, and website program all went live on 15 August 2026 - three days before first public footage drop. Leak cadence and token pumping tightly coupled.
All five video files share identical FFmpeg 6.1 toolchain:
Encoder : Lavc60.31.102 libx265
Container : Lavf60.16.100
Color : 10-bit BT.2020
FPS : 30.00 constant
In fifth video (plane.mp4) player actively shoots letters LEEK into wall with real-time bullet holes and recoil. Live interactive input. Not pre-rendered asset.
Take-Two issued aggressive worldwide DMCA takedowns. Consensus: footage is authentic Rockstar material. Surrounding operation functions as crypto promotion using real leaks as bait.
2. Channel Structure and the No-Twitter Watermark
Cyberleek watermark in junkies.mp4
Cyberleek's fourth video contains hardcoded watermark stating the brand does not operate a Twitter/X presence. Community researchers and official Telegram channel used this to flag large promoter accounts (@cyberleekario, @MrCyberLeek and others) as imposters.
cyberleekario is secondary Telegram channel (approx 12-14.5k subscribers at time of IntCyberDigest post) + now-suspended X account. It posted additional clips and the Google Drive folder that became the pivot of the Spanish attribution. Best understood as mirror / reposter / opportunistic copycat. Not primary source of material or on-chain infrastructure.
3. The IntCyberDigest Claim and Its Problems
On 20 August 2026 @IntCyberDigest published thread claiming operator of cyberleekario was Spaniard using moniker GnomodelincuenT, linked via:
1. Google Drive folder shared in Telegram channel
- Ownership by [email protected]
- Reverse lookup on osint.industries → matching profile picture + name
IntCyberDigest attribution thread
Hours earlier same account had been Community-Noted for sharing fabricated CS.RIN.RU forum screenshot while teasing identity reveal. Account asked followers to help vote the note down. Publishing fabricated screenshot immediately before a doxx is serious reliability red flag.
Named individual responded on X with a public denial:
"Ya me imaginaba yo que algún idiota intentaría robarme la identidad. Pues no, xd. Se escribe gomno."
The handle maps to a real Spanish teenage internet persona active around 2012-2013:
- cuantocabron.com meme profile
- 2013 YouTube cinnamon challenge video under "Gnomo el Canelita / Gnomo Delincuente"
- Twitter accounts created 2013
"Gnomo delincuente" is basic Spanish wordplay. Long-dormant civilian meme identity. Not operational alias.
Have I Been Pwned result for [email protected]
Personal address exposed across multiple breaches is exactly the type of long-lived civilian account a competent operator would avoid for distributing stolen Rockstar material.
4. Stronger Alternative Trail: German/Swiss Forum History
Independent research (zyrexdz repository and community investigators) has documented a multi-year footprint under the exact handle cyberleek:
3 January 2018 SzeneBox introduction by cyberleek
- 3 January 2018: User cyberleek (dark flaming skull avatar) introduces himself on the German underground forum szenebox.org as 25-30 years old. Interests: Linux, 3D printing, Raspberry Pi, web security. Native German/Swiss-German ("Moiin", later "Grüsse").
- Same period: Operates second account tech-forum and the Swiss website
tech-forum.ch. - Explicit linkage of both accounts in a January 2018 post, including XMPP contact cookie@im-
tech-forum.chand admin@tech-forum.ch. - Official Twitter
@T3chF0rumcreated the same day as the SzeneBox introduction, same flaming skull avatar. Password reset routes to admin@tech-forum.ch.
@T3chF0rum X account
tech-forum.ch closure notice
Historical Swiss WHOIS (pre-2021 transparency) shows tech-forum.ch registered December 2017 by a Swiss individual named Manuel H. in Lenzburg. Same user remained active on SzeneBox into 2023 discussing BreachForums mirrors, Perfect Privacy VPN, and exploit hunting.
Primary server infrastructure used in the 2026 operation resolves to Hetzner Online in Nuremberg, Bavaria (IP 49.13.45.141).
This profile describes a German- or Swiss-speaking adult now approximately 33-38 years old with a long technical history. Far better fit for the sophistication of the on-chain setup than a 2013 Spanish meme teenager.
5. On-Chain Control Architecture and Funding
Website domains (cyberleek.ar.io + typo variants), content uploads, and Solana voting program were prepared as a coordinated cluster.
- Shared funding source wallet funded both the ArNS domain controller and the Turbo uploader.
- Master Solana operator key:
6Nq6KAzFKFCKDXYg1kqs23EuBBEWoWAgmBQAQtq4FaF3
This key signed publication of Videos 3, 4 and 5 as well as poll settlement.
- Upstream funding traces to multiple KuCoin withdrawals beginning 29 May 2026. KuCoin has required KYC for withdrawals since 2023. A verified identity therefore exists in exchange records.
Solana master key activity
Cyberleek official site
Monetization infrastructure was live three days before any gameplay footage was released publicly. Inconsistent with the operational profile of a long-dormant personal Spanish Gmail.
6. Relationship to the 2022 Leak
Arion Kurtaj and the 2022 teapotuberhacker case
The September 2022 leak was the work of Arion Kurtaj (Lapsus$). Sentenced December 2023. As of mid-2026 he remains in the UK prison system awaiting retrial. Cyberleek is a separate later actor. Cyberleek has referred to Kurtaj as "our colleague" but there is no verified operational continuity.
7. Evidence Grading
| Explanation for Drive to Gmail link | Plausibility | Notes |
|---|---|---|
| Stale / planted or coincidental civilian account | High | Matches 2012-2013 Spanish persona + denial |
| Shared or compromised Drive used as throwaway | Moderate | Consistent with 7 HIBP breaches |
| Reused throwaway that overlaps a real identity | Moderate | Possible but still not core operator |
| Correct attribution of secondary channel only | Low-Moderate | Not independently corroborated |
| Correct attribution of primary Cyberleek operator | Very Low | Contradicted by German/Swiss trail, watermark, on-chain setup |
osint.industries is a legitimate platform. A name-and-picture match confirms account existence. It does not confirm the account owner conducted the leak. Shared, recycled or compromised accounts produce false positives.
Conclusion
IntCyberDigest's attribution is a classic case of over-confident single-source OSINT that confuses a secondary distribution channel with the primary actor. The German/Swiss multi-year technical footprint, the explicit no-Twitter watermark, the three-day-early on-chain infrastructure, and the KuCoin funding trail form a significantly more coherent picture of the core Cyberleek operator.
This report will be updated as new primary evidence becomes available.
VULONE Research Team 21 August 2026