
The LeakNet ransomware group is now employing the ClickFix method to initially break into company networks, utilizing a malware loader powered by the open-source Deno runtime for JavaScript and TypeScript.
The attacker leverages the authentic Deno to decode and run a malicious payload directly in the system’s RAM, reducing the amount of evidence left on the hard drive and making it harder to detect.
LeakNet is a fairly new ransomware group, appearing around the close of 2024. They typically target about three victims each month, but this could increase with the introduction of these new methods.
ClickFix is a common social engineering attack that deceives users into executing harmful commands on their computers through deceptive messages. Several ransomware groups, including Termite and Interlock, have adopted this technique.
In LeakNet’s situation, the ClickFix tactic leads to the deployment of a Deno-based loader, executing a JavaScript payload within the system’s memory.
ReliaQuest dubs this tactic a “bring your own runtime” (BYOR) attack, as Deno is a trustworthy JavaScript/TypeScript runtime that enables JS/TS code to run on a system outside of a web browser.
Since Deno is digitally signed and legitimate, it avoids being blocked by security lists and filters that target unknown executable files.
“Instead of deploying a custom malware loader thatâs more likely to be flagged, the attackers install the legitimate Deno executable and use it to run malicious code,” ReliaQuest explains.
“In observed activity, that process was initiated through Visual Basic Script (VBS) and PowerShell scripts, cleverly named Romeo*.ps1 and Juliet*.vbs.”
The practice of using Deno for direct execution in memory is crucial, as it leaves little digital trace and can appear as a standard developer task.
Once executed, the malicious code gathers system information, assigns a unique ID to the victimized machine, and connects to the command-and-control server (C2) to retrieve the subsequent payload. It also maintains a persistent loop, constantly checking with the C2 for new instructions.
In the post-exploitation stage, LeakNet employs DLL sideloading (jli.dll loaded through Java in C:\ProgramData\USOShared), C2 beaconing, credential harvesting via ‘klist’ enumeration, movement within the network using PsExec, and payload staging and data theft that involves exploiting Amazon S3 buckets.
The researchers highlight that the consistent and repeatable nature of the attack provides possibilities for defenders to detect it.
Key indicators of potential LeakNet attacks include Deno running outside of typical development environments, suspicious ‘misexec’ executions initiated from web browsers, unusual PsExec usage, unexpected communication to S3, and DLL sideloading in uncommon locations.
#“clickfix” #and #attacks #conduct #deno #discreet #employs #environment #leaknet #news #ransomware #runtime #the #under-the-radar — News
© Bulletproof Servers. All rights reserved.