Threats · 182 days ago
LeakNet uses ClickFix social engineering on compromised websites to trick users into executing commands for initial access. Operators then run the legitimate Deno runtime to execute a JavaScript in-memory loader, reducing disk artifacts and increasing stealth. Observed targeting includes manufacturing, critical infrastructure, and others.
2 sources covering this story
LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader
LeakNet uses ClickFix via compromised sites to gain access, enabling stealth attacks and scalable ransomware operations.
LeakNet ransomware uses ClickFix, Deno runtime in stealthy attacks
The LeakNet ransomware gang is now using the ClickFix technique for initial access into corporate environments and deploys a malware loader based on the open-source Deno runtime for JavaScript and TypeScript.
Part of the PlainSec briefing for 2026-03-18