As cited
Copy frozen at (site build).
ransomware
Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat
LeakNet ransomware operators are expanding their attack capabilities by adopting ClickFix social engineering lures hosted on compromised websites and deploying a Deno-based in-memory loader for command-and-control delivery. The group maintains a consistent post-exploitation sequence across incidents, including jli.dll side-loading into Java, PsExec lateral movement, and S3 bucket payload staging. This shift toward self-directed campaigns reduces LeakNet's reliance on initial access brokers and accelerates their timeline from initial compromise to encryption.
Why it matters: Organizations must implement layered defenses against LeakNet's evolving tactics: block newly registered domains, restrict Win-R access, limit PsExec to authorized administrators, and monitor for suspicious behavior post-compromise, as the group is scaling operations and moving away from detectable initial access broker transactions.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ransomware
Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat
LeakNet ransomware operators are expanding their attack capabilities by adopting ClickFix social engineering lures hosted on compromised websites and deploying a Deno-based in-memory loader for command-and-control delivery. The group maintains a consistent post-exploitation sequence across incidents, including jli.dll side-loading into Java, PsExec lateral movement, and S3 bucket payload staging. This shift toward self-directed campaigns reduces LeakNet's reliance on initial access brokers and accelerates their timeline from initial compromise to encryption.
Why it matters: Organizations must implement layered defenses against LeakNet's evolving tactics: block newly registered domains, restrict Win-R access, limit PsExec to authorized administrators, and monitor for suspicious behavior post-compromise, as the group is scaling operations and moving away from detectable initial access broker transactions.
- Source published
- First seen by Cybersecurity Tracker