The LeakNet ransomware group has adopted the ClickFix social engineering tactic , via compromised websites, to gain initial access to systems. The use of ClickFix , where users are tricked into manually executing malicious commands to address non-existent errors, is a departure from traditional methods of gaining initial access.

According to a white paper published by ReliaQuest, LeakNet has abandoned the use of stolen credentials obtained from initial access brokers (IABs). This strategic shift offers multiple benefits, including cost reduction, elimination of third-party vendor dependencies, etc.
See also: Velvet Tempest: Distribution of DonutLoader and CastleRAT via ClickFix techniques
The second important element of these attacks is the use of a staged command-and-control (C2) loader based on the Deno JavaScript runtime to execute malicious payloads directly in memory. This “bring your own runtime” (BYOR) approach allows attackers to minimize on-disk resources and avoid detection, as Deno can look like legitimate developer activity.
The evolution of LeakNet and the adoption of ClickFix
LeakNet first emerged in November 2024 , describing itself as a “digital watchdog” and framing its activities as focused on internet freedom and transparency. According to data collected by Dragos , the group has also targeted industrial entities, expanding the scope of its attacks beyond traditional targets.
See also: ClickFix attacks spread MacSync infostealer
In these attacks, legitimate but compromised websites are used to serve fake CAPTCHA verification checks that instruct users to copy and paste an “ msiexec.exe ” command into the Windows Run dialog . The attacks are not limited to a specific industry, but instead cast a wide net to infect as many victims as possible.

The growth comes as more threat actors adopt the ClickFix. Trusted, everyday workflows entice users to execute deceptive commands via legitimate Windows.
In addition to using ClickFix to start the attack chain, LeakNet uses a loader, based on Deno, to execute Base64-encoded JavaScript directly in memory (to minimize disk footprint and avoid detection). The payload is designed to scan the compromised system, communicate with an external server to retrieve next-stage malware, and enter a detection loop that repeatedly retrieves and executes additional code via Deno.
The activity, after the initial breach, follows a consistent methodology: it begins by using DLL side-loading to launch a malicious DLL delivered via the loader. This is followed by side-traffic using PsExec , data extraction, and encryption. The group executes the command “ cmd.exe /c klist ”, a built-in Windows command that displays active authentication credentials on the compromised system.
See also: New ClickFix attacks infect systems with LummaStealer

Security recommendations
Organizations are advised to monitor for Deno outside of development environments, suspicious msiexec from browsers, abnormal PsExec , outbound S3 traffic , and DLL side-loading to non-standard paths such as C:\ProgramData\USOShared . Additionally, user training on Run dialog box commands and deploying EDRs for klist/PsExec/Deno behaviors are critical to preventing such attacks.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
