216.73.217.98

Casting a Wider Net: Scaling Threat

· Published 18/03/2026 10:53 · Modified 18/03/2026 11:20

Export JSON

Essential information

Published
18/03/2026 10:53
Modified
18/03/2026 11:20
Tags
2026-03-18 clickfix deno in-memory execution lateral movement psexec ransomware s3 bucket side-loading social engineering
Related entities
5 observables, 1 intrusion sets (apt), 7 techniques (mitre), 12 others

Description

LeakNet, a operator, has expanded its initial access methods by utilizing lures on compromised websites and implementing a new -based, in-memory loader. The group has shifted from relying on initial access brokers to running its own campaigns. LeakNet's post-exploitation playbook remains consistent, involving jli.dll , -based , and payload staging. The loader executes base64-encoded payloads in memory, making detection challenging for traditional security tools. Defenders are advised to focus on behavioral signals and implement measures such as blocking newly registered domains, restricting Win-R access, and limiting usage to authorized administrators.

External references