LeakNet uses ClickFix social engineering on compromised websites to trick users into executing commands for initial access. Operators then run the legitimate Deno runtime to execute a JavaScript in-memory loader, reducing disk artifacts and increasing stealth. Observed targeting includes manufacturing, critical infrastructure, and others.
Part of the PlainSec briefing for 2026-03-18