LeakNet ransomware uses ClickFix, Deno runtime in stealthy attacks
ID: 2d2f52aa-70ee-5407-98c1-3718e727131d
STIX ID: report--2d2f52aa-70ee-5407-98c1-3718e727131d
Feed Name: Bleeping Computer
LeakNet ransomware is using ClickFix social-engineering to trick victims into running the legitimate Deno runtime as a 'bring your own runtime' loader that executes malicious JS/TS in memory to minimize forensic traces; post-compromise activity includes DLL sideloading, PsExec-based lateral movement, credential discovery, C2 beaconing, and data exfiltration via Amazon S3, with defenders advised to watch for Deno running outside development contexts, abnormal PsExec activity, unexpected S3 traffic, and DLL sideloading in unusual directories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
