HomeSecurityLeakNet Ransomware group uses ClickFix techniques

The LeakNet Ransomware group uses ClickFix techniques

The LeakNet ransomware group has adopted the ClickFix social engineering tactic , via compromised websites, to gain initial access to systems. The use of ClickFix , where users are tricked into manually executing malicious commands to address non-existent errors, is a departure from traditional methods of gaining initial access.

LeakNet Ransomware

According to a white paper published by ReliaQuest, LeakNet has abandoned the use of stolen credentials obtained from initial access brokers (IABs). This strategic shift offers multiple benefits, including cost reduction, elimination of third-party vendor dependencies, etc.

See also: Velvet Tempest: Distribution of DonutLoader and CastleRAT via ClickFix techniques

The second important element of these attacks is the use of a staged command-and-control (C2) loader based on the Deno JavaScript runtime to execute malicious payloads directly in memory. This “bring your own runtime” (BYOR) approach allows attackers to minimize on-disk resources and avoid detection, as Deno can look like legitimate developer activity.

The evolution of LeakNet and the adoption of ClickFix

LeakNet first emerged in November 2024 , describing itself as a “digital watchdog” and framing its activities as focused on internet freedom and transparency. According to data collected by Dragos , the group has also targeted industrial entities, expanding the scope of its attacks beyond traditional targets.

See also: ClickFix attacks spread MacSync infostealer

In these attacks, legitimate but compromised websites are used to serve fake CAPTCHA verification checks that instruct users to copy and paste an “ msiexec.exe ” command into the Windows Run dialog . The attacks are not limited to a specific industry, but instead cast a wide net to infect as many victims as possible.

The LeakNet Ransomware group uses ClickFix techniques

The growth comes as more threat actors adopt the ClickFix. Trusted, everyday workflows entice users to execute deceptive commands via legitimate Windows.

In addition to using ClickFix to start the attack chain, LeakNet uses a loader, based on Deno, to execute Base64-encoded JavaScript directly in memory (to minimize disk footprint and avoid detection). The payload is designed to scan the compromised system, communicate with an external server to retrieve next-stage malware, and enter a detection loop that repeatedly retrieves and executes additional code via Deno.

The activity, after the initial breach, follows a consistent methodology: it begins by using DLL side-loading to launch a malicious DLL delivered via the loader. This is followed by side-traffic using PsExec , data extraction, and encryption. The group executes the command “ cmd.exe /c klist ”, a built-in Windows command that displays active authentication credentials on the compromised system.

See also: New ClickFix attacks infect systems with LummaStealer

The LeakNet Ransomware group uses ClickFix techniques

Security recommendations

Organizations are advised to monitor for Deno outside of development environments, suspicious msiexec from browsers, abnormal PsExec , outbound S3 traffic , and DLL side-loading to non-standard paths such as C:\ProgramData\USOShared . Additionally, user training on Run dialog box commands and deploying EDRs for klist/PsExec/Deno behaviors are critical to preventing such attacks.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS