LeakNet Ransomware Uses ClickFix via Hacked Sites Deploys Deno In-Memory Loader
The ClickFix social engineering technique, which is distributed via hacked websites, has been used as an initial entry method by the ransomware operation known as LeakNet.
According to a technical report released today by ReliaQuest, the use of ClickFix, which deceives users into manually executing malicious commands to fix nonexistent errors, is different from depending on conventional methods for gaining initial access, like using credentials that were stolen from initial access brokers (IABs).
The employment of a staged command-and-control (C2) loader based on the Deno JavaScript runtime to run malicious payloads directly in memory is the second crucial component of these assaults.
According to the cybersecurity firm, the most important lesson here is that both entry routes re...










