CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2119

As cited

Copy frozen at (site build).

ransomware

Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat

LeakNet ransomware operators are expanding their attack capabilities by adopting ClickFix social engineering lures hosted on compromised websites and deploying a Deno-based in-memory loader for command-and-control delivery. The group maintains a consistent post-exploitation sequence across incidents, including jli.dll side-loading into Java, PsExec lateral movement, and S3 bucket payload staging. This shift toward self-directed campaigns reduces LeakNet's reliance on initial access brokers and accelerates their timeline from initial compromise to encryption.

Why it matters: Organizations must implement layered defenses against LeakNet's evolving tactics: block newly registered domains, restrict Win-R access, limit PsExec to authorized administrators, and monitor for suspicious behavior post-compromise, as the group is scaling operations and moving away from detectable initial access broker transactions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat

LeakNet ransomware operators are expanding their attack capabilities by adopting ClickFix social engineering lures hosted on compromised websites and deploying a Deno-based in-memory loader for command-and-control delivery. The group maintains a consistent post-exploitation sequence across incidents, including jli.dll side-loading into Java, PsExec lateral movement, and S3 bucket payload staging. This shift toward self-directed campaigns reduces LeakNet's reliance on initial access brokers and accelerates their timeline from initial compromise to encryption.

Why it matters: Organizations must implement layered defenses against LeakNet's evolving tactics: block newly registered domains, restrict Win-R access, limit PsExec to authorized administrators, and monitor for suspicious behavior post-compromise, as the group is scaling operations and moving away from detectable initial access broker transactions.

VendorsAmazon Web ServicesOracle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary