logo

Abusing ClickOnce

ID: 487659cf-77a0-5117-afbb-b5cb3957cf6a

STIX ID: report--487659cf-77a0-5117-afbb-b5cb3957cf6a

Feed Name: Zscaler Security Research Blog

Threat Score
30/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

The report demonstrates how attackers can abuse Internet Explorer's ClickOnce deployment popups to trick users into installing malware by spoofing the application Name, truncating the From domain to appear legitimate, and using legitimate or stolen code-signing certificates for the Publisher field; the technique is easy to implement, effective for social engineering, and should be monitored though broad attacks have not been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.