LeakNet Expands Stealthy Ransomware Access Across Sectors
LeakNet uses ClickFix social engineering on compromised websites to trick users into executing commands for initial access. Operators then run the legitimate Deno runtime to execute a JavaScript in-memory loader, reducing disk artifacts and increasing stealth. Observed targeting includes manufacturing, critical infrastructure, and others.
LeakNet ransomware uses ClickFix, Deno runtime in stealthy attacks
The LeakNet ransomware gang is now using the ClickFix technique for initial access into corporate environments and deploys a malware loader based on the open-source Deno runtime for JavaScript and TypeScript.