logo

LeakNet boosts ransomware with ClickFix lures, stealthy Deno loader

ID: ebc3faf4-c1aa-5bdd-be3f-00e3cc05dedc

STIX ID: report--ebc3faf4-c1aa-5bdd-be3f-00e3cc05dedc

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-03-18

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

LeakNet is scaling its ransomware operation by delivering ClickFix social-engineering lures on compromised legitimate websites that trick users into running msiexec commands, then deploying a stealthy Deno-based in-memory loader and follow-on post-exploitation techniques (DLL sideloading, PsExec, Kerberos enumeration, and S3-based staging/exfiltration). The report highlights consistent TTPs across incidents, detection opportunities (unusual msiexec from browsers/Win-R, Deno running base64 data URLs, java.exe loading jli.dll), and provides a list of associated malicious domains, IPs, and S3 buckets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.