Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks
ID: 4552dba3-5197-59b4-a552-bf0d91cd5812
STIX ID: report--4552dba3-5197-59b4-a552-bf0d91cd5812
Feed Name: Bleeping Computer
Trellix analyzed the OneClik engagement—a ClickOnce-based campaign using a .NET loader (OneClikNet) to deliver a Go backdoor called RunnerBeacon that communicated via AWS services to hide C2. The report covers delivery (phishing to ClickOnce .application), AppDomainManager injection for stealthy payload loading, RunnerBeacon’s RC4/MessagePack C2 and modular commands (remote shell, file ops, port scanning, SOCKS5, process injection), and IOC listings, while noting the operation was a red-team simulation emulating China-affiliated TTPs rather than confirmed malicious attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
