logo

LeakNet Scales Ransomware Operations With ClickFix Lures and Stealthy Deno Loader

ID: aaa308b1-8906-5b4d-a039-e335fcfe3a29

STIX ID: report--aaa308b1-8906-5b4d-a039-e335fcfe3a29

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

LeakNet is scaling up operations by using fake verification pages (ClickFix) hosted on legitimate sites and a novel in-memory loader that runs malicious code via the legitimate Deno runtime; this combination enables wide phishing-style campaigns, evades signature-based defenses, and feeds a consistent post-exploitation chain that leads to ransomware deployment, with observable IoCs and actionable defender mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.