Casting a Wider Net: Scaling Threat
Essential information
- Published
- 18/03/2026 10:53
- Modified
- 18/03/2026 11:20
- Tags
- 2026-03-18 clickfix deno in-memory execution lateral movement psexec ransomware s3 bucket side-loading social engineering
- Related entities
- 5 observables, 1 intrusion sets (apt), 7 techniques (mitre), 12 others
Description
LeakNet, a ransomware operator, has expanded its initial access methods by utilizing ClickFix lures on compromised websites and implementing a new Deno-based, in-memory loader. The group has shifted from relying on initial access brokers to running its own campaigns. LeakNet's post-exploitation playbook remains consistent, involving jli.dll side-loading, PsExec-based lateral movement, and S3 bucket payload staging. The Deno loader executes base64-encoded payloads in memory, making detection challenging for traditional security tools. Defenders are advised to focus on behavioral signals and implement measures such as blocking newly registered domains, restricting Win-R access, and limiting PsExec usage to authorized administrators.