logo

Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks

ID: 4552dba3-5197-59b4-a552-bf0d91cd5812

STIX ID: report--4552dba3-5197-59b4-a552-bf0d91cd5812

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-06-25

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

Trellix analyzed the OneClik engagement—a ClickOnce-based campaign using a .NET loader (OneClikNet) to deliver a Go backdoor called RunnerBeacon that communicated via AWS services to hide C2. The report covers delivery (phishing to ClickOnce .application), AppDomainManager injection for stealthy payload loading, RunnerBeacon’s RC4/MessagePack C2 and modular commands (remote shell, file ops, port scanning, SOCKS5, process injection), and IOC listings, while noting the operation was a red-team simulation emulating China-affiliated TTPs rather than confirmed malicious attribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.