As cited
Copy frozen at (site build).
threat intel
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever
This article discusses continued abuse of Microsoft's ClickOnce deployment technology by threat actors to maintain persistence and evade detection. ClickOnce, designed for legitimate software deployment, is being weaponized to establish long-term access to compromised systems. The piece examines techniques threat actors use to exploit this technology and recommendations for defenders.
Why it matters: Security practitioners need to understand ClickOnce abuse vectors to detect and block malicious deployments targeting their users and endpoints, as this attack method enables persistence that standard defenses may not catch.
- First seen by Cybersecurity Tracker