
The LeakNet ransomware group is now using a social engineering trick called ClickFix, spread through hacked websites, to get into systems.
Instead of relying on typical methods like buying stolen login information from initial access brokers (IABs), LeakNet is using ClickFix, where people are tricked into running harmful commands themselves to fix fake errors. This is according to a report by ReliaQuest published today.
Another key point is that these attacks use a special program built on the Deno JavaScript platform to run harmful code directly in the computer’s memory.
“The main thing to remember is that both ways of getting in lead to the same steps after the initial compromise,” the cybersecurity company stated. “This gives defenders something specific to look for: known behaviors that can be found and stopped at each stage, long before the ransomware is deployed, no matter how LeakNet got in.”
LeakNet first appeared in November 2024, calling itself a “digital watchdog” and portraying its actions as supporting internet freedom and openness. Dragos reported that the group has also attacked industrial organizations.
Using ClickFix to breach victims offers some benefits, mainly that it reduces reliance on other vendors, lowers costs per victim, and removes the bottleneck of waiting for useful accounts to become available.
In these attacks, hacked legitimate websites show fake CAPTCHA tests that tell users to copy and paste a “msiexec.exe” command into the Windows Run dialog. These attacks aren’t limited to a specific industry but are used broadly to infect as many victims as possible.
This development occurs as more attackers are using ClickFix, as it takes advantage of trusted, everyday actions to trick users into running malicious commands through legitimate Windows tools in a way that seems normal and safe.
“LeakNet’s use of ClickFix is the first known expansion of the group’s initial access methods and a significant strategic shift,” ReliaQuest commented.
“By moving away from IABs, LeakNet eliminates a limitation that naturally restricted how quickly and widely it could operate. And because ClickFix is distributed through legitimate, yet compromised, websites, it doesn’t have the same obvious network signals as attacker-owned infrastructure.”
In addition to using ClickFix to start the attack, LeakNet is thought to be using a Deno-based program to run Base64-encoded JavaScript directly in memory, reducing traces on the disk and avoiding detection. The program is designed to identify the compromised system, contact an external server for further malware, and repeatedly fetch and run additional code via Deno.
ReliaQuest also noted a separate intrusion attempt where attackers used Microsoft Teams phishing to socially engineer a user into launching a program that ended with a similar Deno-based loader. While the attacker is unknown, the use of the bring your own runtime (BYOR) approach suggests that LeakNet is broadening its initial access methods or that other attackers are using this technique.
LeakNet’s actions after the initial compromise are consistent: it begins with DLL side-loading to launch a malicious DLL delivered via the loader, then moves laterally using PsExec, steals data, and encrypts files.
“LeakNet runs cmd.exe /c klist, a built-in Windows command that displays active login credentials on the compromised system. This shows the attacker which accounts and services are already accessible without needing new credentials, allowing them to move faster and more effectively,” ReliaQuest explained.
“For storage and data theft, LeakNet uses S3 buckets, making it look like normal cloud traffic to avoid detection.”
This development comes as Google revealed that Qilin (aka Agenda), Akira (aka RedBike), Cl0p, Play, SafePay, INC Ransom, Lynx, RansomHub, DragonForce (aka FireFlame and FuryStorm), and Sinobi were the top 10 ransomware groups with the most victims listed on their data leak sites.
“In one-third of incidents, the initial access method was confirmed or suspected exploitation of vulnerabilities, most often in common VPNs and firewalls,” Google Threat Intelligence Group (GTIG) reported, adding that 77% of analyzed ransomware attacks involved suspected data theft, up from 57% in 2024.
“Despite ongoing issues caused by actor conflicts and disruption, ransomware attackers are still highly motivated, and the extortion ecosystem is still resilient. Several signs suggest that the overall profitability of these operations is declining, and some attackers are shifting from targeting large companies to targeting more smaller organizations.”
#“clickfix” #deno #directly #hacked #into #leaknet #loads #memory. #news #ransomware #spreads #then #through #using #websites — News
© Bulletproof Servers. All rights reserved.