CARDS
CARDS
LeakNet delivered ClickFix lures through compromised legitimate websites and used a Deno-based in-memory loader before a repeatable post-access sequence of jli.dll side-loading, PsExec lateral movement, and S3 payload staging.
Last updated Jul 17, 2026, 12:00 PM EDT
Evidence Boundary
Bottom Line Up Front
LeakNet delivered ClickFix lures through compromised legitimate websites and used a Deno-based in-memory loader before a repeatable post-access sequence of jli.dll side-loading, PsExec lateral movement, and S3 payload staging.[1]
The chain shortens the path from a user-executed ClickFix command to lateral movement and ransomware staging while leaving fewer conventional files for signature-based controls.[1]
Hunt for unusual msiexec execution, Deno outside development workflows, Java loading jli.dll from USOShared, unauthorized PsExec, and connections to attacker-controlled or anomalous S3 staging paths.[1]
Decision Summary
LeakNet delivered ClickFix lures through compromised legitimate websites and used a Deno-based in-memory loader before a repeatable post-access sequence of jli.dll side-loading, PsExec lateral movement, and S3 payload staging.
The retained record scopes this as ransomware intrusion / clickfix / living off the land activity during 2026-03-17. The chain shortens the path from a user-executed ClickFix command to lateral movement and ransomware staging while leaving fewer conventional files for signature-based controls.[1]
Hunt for unusual msiexec execution, Deno outside development workflows, Java loading jli.dll from USOShared, unauthorized PsExec, and connections to attacker-controlled or anomalous S3 staging paths.[1]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for the observed intrusion chain; the source does not establish that every attempt reached encryption..[1]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
Treat the sequence as observed LeakNet behavior, not a universal playbook or confirmation that every actor claim represents a successful intrusion.
Evidence Controls
IntelliOS
None Found
Citations