Minacce · 198 giorni fa
Il gruppo impiega ClickFix su siti compromessi per indurre utenti a eseguire comandi e ottenere accesso iniziale. Gli operatori installano il runtime Deno legittimo per eseguire in-memory un loader JavaScript, riducendo artefatti su disco e aumentando la furtività. Obiettivi osservati includono manifatturiero, infrastrutture critiche e altri settori.
2 fonti che coprono questa storia
LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader
LeakNet uses ClickFix via compromised sites to gain access, enabling stealth attacks and scalable ransomware operations.
LeakNet ransomware uses ClickFix, Deno runtime in stealthy attacks
The LeakNet ransomware gang is now using the ClickFix technique for initial access into corporate environments and deploys a malware loader based on the open-source Deno runtime for JavaScript and TypeScript.
Part of the PlainSec briefing for 2026-03-18