logo

LeakNet Changes Tactics, But Consistency Gives Defenders an Advantage 

ID: b7d13ffb-36cf-55b6-be45-f3a98008a030

STIX ID: report--b7d13ffb-36cf-55b6-be45-f3a98008a030

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-04-01

Date Updated: 2026-04-22

Author: Teri Robinson

...
...

ReliaQuest analysis shows ransomware operator LeakNet scaling and evolving its tradecraft: operators are using ClickFix social-engineering lures on compromised trusted sites to trick users into running commands, and a Deno-based in-memory loader (JavaScript/TypeScript runtime) to execute payloads stealthily. LeakNet is moving away from initial access brokers to run its own campaigns while following a consistent post-exploitation sequence (execution, lateral movement, payload staging), enabling defenders to detect and disrupt the attack chain; recommended mitigations include blocking newly registered domains, restricting Win+R usage, and preventing unauthorized PsExec execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.