CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 653

As cited

Copy frozen at (site build).

threat intel

New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

This article discusses continued abuse of Microsoft's ClickOnce deployment technology by threat actors to maintain persistence and evade detection. ClickOnce, designed for legitimate software deployment, is being weaponized to establish long-term access to compromised systems. The piece examines techniques threat actors use to exploit this technology and recommendations for defenders.

Why it matters: Security practitioners need to understand ClickOnce abuse vectors to detect and block malicious deployments targeting their users and endpoints, as this attack method enables persistence that standard defenses may not catch.

First seen by Cybersecurity Tracker

Source attribution

Glossary