CARDS
CARDS
ReliaQuest observed ClickFix lures on compromised legitimate websites, a Deno-based in-memory loader, jli.dll side-loading, PsExec lateral movement, and S3 payload staging across confirmed incidents.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Entity Type
Ransomware profile
First Seen
2025-08-01
Last Seen
2026-03-17
Profile Updated
Jul 16, 2026, 8:00 PM EDT
Victim Count
Not available
Origin
Unknown
Motivation
Financially motivated ransomware and extortion
Primary Access Pattern
T1189 Drive-by Compromise (initial-access)
Objective
Financially motivated ransomware and extortion
Identity
Aliases
Source Boundary
reliaquest.com is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure
Target Sectors
Associated Activity
ATT&CK IDs
Campaign Context
| Campaign / Operation | Source-Backed Context |
|---|---|
| LeakNet ClickFix / Deno Intrusion Chain1 | LeakNet ClickFix / Deno Intrusion Chain is retained in the campaign database for LeakNet. LeakNet delivered ClickFix lures through compromised legitimate websites and used a Deno-based in-memory loader before jli.dll side-loading, PsExec lateral movement, and S3 payload staging. |
Indicators
No public IOC values are currently retained in IntelliOS for this profile. Future enrichment can add cited observables from SOCRadar, Microsoft threat intelligence, Google/Mandiant, CrowdStrike, MITRE CTI, CISA, vendor reports, and other reliable open sources.
Source coverage: 1 source group tracked; 0 currently contribute retained observable or context rows.
Retained Public Observables
No public IOC values are currently retained in IntelliOS for this profile. Future enrichment can add cited observables from SOCRadar, Microsoft threat intelligence, Google/Mandiant, CrowdStrike, MITRE CTI, CISA, vendor reports, and other reliable open sources.
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar | N/A | 0 | Profile retained; no SOCRadar IOC count currently stored. |
IntelliOS Intel Products
None Found
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| reliaquest.com | LeakNet | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | LeakNet | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | ReliaQuest: Casting a Wider Net https://reliaquest.com/blog/threat-spotlight-casting-a-wider-net-clickfix-deno-and-leaknets-scaling-threat/ | ReliaQuest Threat Research |
| 2 | Cloud Security Alliance: LeakNet research note https://labs.cloudsecurityalliance.org/research/csa-research-note-leaknet-ransomware-clickfix-deno-loader-20/ | Cloud Security Alliance |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for LeakNet.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |