logo

LeakNet Ransomware Uses ClickFix via Hacked Sites, Deploys Deno In-Memory Loader

ID: 198b564d-3f22-5143-bf7f-440579244a98

STIX ID: report--198b564d-3f22-5143-bf7f-440579244a98

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-03-17

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**LeakNet ransomware operation** has shifted to ClickFix social engineering delivered through compromised legitimate websites to trick users into running msiexec commands, and employs a staged Deno-based in-memory loader to fetch and execute Base64-encoded JavaScript; post-compromise activity includes DLL side-loading, PsExec lateral movement, S3-based data exfiltration, and encryption, with broad targeting including industrial entities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.