LeakNet Changes Tactics, But Consistency Gives Defenders an Advantage
ID: b7d13ffb-36cf-55b6-be45-f3a98008a030
STIX ID: report--b7d13ffb-36cf-55b6-be45-f3a98008a030
Feed Name: Security Boulevard
ReliaQuest analysis shows ransomware operator LeakNet scaling and evolving its tradecraft: operators are using ClickFix social-engineering lures on compromised trusted sites to trick users into running commands, and a Deno-based in-memory loader (JavaScript/TypeScript runtime) to execute payloads stealthily. LeakNet is moving away from initial access brokers to run its own campaigns while following a consistent post-exploitation sequence (execution, lateral movement, payload staging), enabling defenders to detect and disrupt the attack chain; recommended mitigations include blocking newly registered domains, restricting Win+R usage, and preventing unauthorized PsExec execution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
