logo

Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat

ID: 56215b09-9f0e-5a64-97f2-4872e031ad5b

STIX ID: report--56215b09-9f0e-5a64-97f2-4872e031ad5b

Feed Name: ReliaQuest Blog

Threat Score
78/100

Date Published: 2026-03-17

Date Updated: 2026-04-29

...
...

ReliaQuest documents that ransomware operator "LeakNet" is expanding by using ClickFix lures delivered via compromised legitimate websites and a Deno-based, in-memory loader to execute base64-encoded JavaScript, establish C2, and then employ a consistent post-exploitation chain (jli.dll DLL sideloading, PsExec lateral movement, and S3 bucket staging); the report includes IOCs, MITRE ATT&CK mappings, and prioritized detection and response guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.