#LeakNet
A ransomware gang that claims to be a group of "investigative journalists"? Meet LeakNet - the group using fake CAPTCHA pages to trick employees into hacking themselves.

Check out my article on the Fortra blog: www.fortra.com/blog/leaknet...
March 20, 2026 at 12:19 PM
ReliaQuest looks at LeakNet, a new ransomware operation that launched last August and has now switched to using ClickFix campaigns for initial entry

reliaquest.com/blog/threat-...
Casting a Wider Net: ClickFix, Deno, and LeakNet’s Scaling Threat
ReliaQuest Threat Researchers report on “LeakNet” adding “ClickFix” through compromised legitimate websites as a newly confirmed initial access method.
reliaquest.com
March 17, 2026 at 1:08 PM
The LeakNet ransomware gang is now using the ClickFix technique for initial access into corporate environments and deploys a malware loader based on the open-source Deno runtime for JavaScript and TypeScript.
LeakNet ransomware uses ClickFix and Deno runtime for stealthy attacks
The LeakNet ransomware gang is now using the ClickFix technique for initial access into corporate environments and deploys a malware loader based on the open-source Deno runtime for JavaScript and TypeScript.
www.bleepingcomputer.com
March 17, 2026 at 12:09 PM
🥷 We're undergoing an in-depth analysis on #Leaknet threat actor.

Emerged in late 2024, has 13 active claimes. Tho it's not absolutely clear if its business model falls under leakware or ransomware.

At this time, we've set the group as monitored, we reserve the right to remove it if leakware.
August 19, 2025 at 4:46 PM
-New Katana botnet linked to 150Gbps attacks
-New CondiBot and Monaco malware
-Handala malware from Stryker attack found on GitHub
-Reports on Payload, Warlock, and LeakNet ransomware
-New leak exposes more APT28 tools
-Xbox One finally got hacked
-Qihoo ships SSL private key
-New CursorJack attack
March 18, 2026 at 9:52 AM
New Ransomware Group: LeakNet

bnlluetsuf6pv7mchgue46h43v66uxtccpg3n5vcdzbeqften5cedlid[.]onion

ahic5qo3qbjgsyv7x2h5w7uh6nuh45km5srblj7i2amxt57xp4wud2qd[.]onion

nleakk6sejx45jxtk7x6iyt65hwvfrkifc5v7ertdlwm3gttbpvlvxqd[.]onion
August 18, 2025 at 2:20 PM
🚨 Massive healthcare data breach!

An extortion group known as #LeakNet claims to have allegedly stolen 11TB of data from NYC Health + Hospitals (#NYCHH), including over 12m patient records.

Listen/Read: hackread.com/leaknet-11tb...

#CyberSecurity #DataBreach #Healthcare #Ransomware
LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach
LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.
hackread.com
July 30, 2026 at 12:28 AM
LeakNet ransomware leverages ClickFix social engineering to deploy a Deno-based loader that runs JavaScript/TypeScript payloads in memory via signed Deno runtime, minimizing disk traces and enabling DLL sideloading and Amazon S3 data exfiltration. #LeakNet #DenoRuntime
LeakNet ransomware uses ClickFix, Deno runtime in stealthy attacks
LeakNet operators are using the ClickFix social‑engineering technique to gain initial access and deploy a Deno-based loader that executes JavaScript/TypeScript payloads directly in memory. By running the legitimate, signed Deno runtime via VBS/PowerShell stagers, the attackers minimize disk artifacts and follow with DLL sideloading, PsExec lateral movement, C2 beaconing, and Amazon S3–based exfiltration. #LeakNet #Deno #ClickFix #ReliaQuest #AmazonS3
www.hendryadrian.com
March 17, 2026 at 2:00 PM
LeakNet ransomware: what you need to know

A ransomware gang that claims to be a group of "investigative journalists"? Meet LeakNet - the group using fake CAPTCHA pages to trick employees into hacking themselves.

Read more in my article on the Fortra blog.
Fortra
www.fortra.com
March 20, 2026 at 10:22 AM
LeakNet Scales Ransomware Operations With ClickFix Lures and Stealthy Deno Loader
LeakNet Scales Ransomware Operations With ClickFix Lures and Stealthy Deno Loader
A ransomware group known as LeakNet has been quietly building a more dangerous attack strategy. Until recently, the group averaged about three victims per month — but new evidence shows it is scaling up fast, adding new tools that most security defenses are not built to catch. LeakNet has introduced two notable additions: a social engineering trick called ClickFix and a stealthy, memory-based loader built on the Deno JavaScript runtime.​ ClickFix is not a brand-new technique in the threat landscape, but LeakNet’s move toward using it marks a significant change in how the group finds its victims. Instead of purchasing stolen access credentials from initial access brokers (IABs) on underground markets, LeakNet now plants fake verification pages on compromised but otherwise legitimate websites. When an unsuspecting user lands on one of these pages, they are shown what looks like a standard Cloudflare Turnstile check and are prompted to manually run a command. There is no specific victim profile here — the group simply casts a wide net and counts on a portion of users to take the bait.​ ReliaQuest analysts identified the activity across multiple recent incidents, attributing it to LeakNet with high confidence based on overlapping infrastructure and consistent tactics, techniques, and procedures (TTPs). The shift away from IABs is deliberate: it removes a dependency that slowed the group down and broadens the pool of potential victims considerably. ClickFix has become a preferred delivery method across the threat landscape, facilitating the distribution of 59% of the top malware families tracked in 2025.​ This shift puts any web-browsing employee at risk. Because the lures are hosted on real websites rather than attacker-owned domains, standard network-layer defenses generate far fewer alerts. The red flag only appears after the user has already run the malicious command, which puts more weight on behavioral monitoring — particularly for suspicious  msiexec  commands and unexpected outbound connections — rather than domain-based blocking alone.​ What makes LeakNet’s current campaign particularly concerning is how both entry paths — ClickFix and Microsoft Teams phishing — feed into the same post-exploitation chain every time. The group moves through execution, lateral movement, and payload staging with the same tools regardless of how it got in. That consistency is a useful signal for defenders: knowing the steps means there are clear points where the attack can be detected and cut short.​ The Stealthy Deno-Based Loader One of the most technically dangerous parts of LeakNet’s updated toolkit is a previously unreported loader built on Deno, a legitimate JavaScript and TypeScript runtime used daily by developers. LeakNet uses a bring-your-own-runtime (BYOR) approach — instead of deploying a custom malicious binary that might trigger security tools, the attackers install the real, trusted Deno executable on the victim’s machine and use it to run harmful code.​ ClickFix lure that incorporates a fake Cloudflare Turnstile verification page (Source – Reliaquest) The loader is activated through PowerShell and Visual Basic Script files, notably named  Romeo*.ps1  and  Juliet*.vbs . Rather than writing a JavaScript file to disk where it could be scanned, LeakNet feeds the payload to Deno as a base64-encoded data URL, which Deno decodes and runs entirely in memory. No standard file ever touches the endpoint, making the entire process nearly invisible to signature-based security tools .​ LeakNet’s attack path (Source – Reliaquest) Once the loader runs, it collects basic system details — username, hostname, memory size, and OS version — then creates a unique victim fingerprint. It connects to attacker-controlled infrastructure to retrieve a victim-specific second-stage payload, prevents duplicate instances by binding to a local port, and then enters a looping cycle of fetching and executing further code in memory.​ To reduce exposure, organizations should block newly registered domains, since LeakNet’s command-and-control servers are typically only weeks old. Regular users should be restricted from running Win-R commands on their workstations, and PsExec should be limited to authorized administrators through Group Policy Objects (GPOs). Security teams should watch for  jli.dll  sideloading in the  C:\ProgramData\USOShared  directory, unusual PsExec activity, and unexpected outbound connections to S3 buckets. Isolating a compromised host the moment post-exploitation behavior is confirmed is the most direct way to break the chain before ransomware reaches deployment.​ Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google . The post LeakNet Scales Ransomware Operations With ClickFix Lures and Stealthy Deno Loader appeared first on Cyber Security News .
cybersecuritynews.com
March 18, 2026 at 2:53 PM
--Yeshiva World News seemingly defaced by Iranian hackers,
--LeakNet ransomware group tries new intrusion techniques,
--Interlock ransomware gang exploits severe flaws in Cisco's FMC,
--Nordstrom customers receive crypto scam emails, 4/6
Statement by Yiff Machine
March 19, 2026 at 2:39 PM
República Dominicana: Banco Vimenca con fuga masiva de datos en la DarkWeb.

www.security-chu.com/2025/12/Banc...

#ciberseguridad #RD #leaknet #DarkWeb
RD: Banco Vimenca con fuga masiva de datos en la DarkWeb
Ciberseguridad-Noticias- Latinoamérica: los atacantes dicen haber robado 190,000 cedulas de identidad de los clientes del Banco Vimenca.
www.security-chu.com
December 27, 2025 at 8:58 PM
LeakNet ransomware group uses ClickFix social engineering via compromised websites for initial access, employing a Deno-based C2 loader to execute payloads in memory, followed by consistent post-exploitation sequences detectable before ransomware deployment.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
March 17, 2026 at 3:12 PM
simple: i am my own bootlegger. i control the topsites that upload the pre-release 0day .NET HyperRarez. i control the pressing plants that master and manufacture the Super-High Density Blu-Spec Gold-NiCad-Coat Discs and leak to the sites. i control the public-facing Quick DDL LeakNet Homepages. i c
November 22, 2024 at 3:35 AM
New post from #Leaknet : Will The Katecho,Llc Be Able To Handle The Hack And Prevent A Data Breach In Time?
More at : https://www.ransomlook.io/group/Leaknet #Ransomware
September 5, 2026 at 11:41 PM
New post from #Leaknet : The 11Tb Nyc Health + Hospitals Archive Is Now Public
More at : https://www.ransomlook.io/group/Leaknet #Ransomware
August 18, 2026 at 12:36 PM
LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach
LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach
LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.
hackread.com
August 8, 2026 at 11:12 PM
New post from #Leaknet : Data Exfiltration Diaries: The Shocking Stories Inside Nyc Health + Hospitals
More at : https://www.ransomlook.io/group/Leaknet #Ransomware
August 6, 2026 at 4:37 AM
LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach

LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.
#hackernews #news
LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach
LeakNet claims it stole 11TB of NYC Health + Hospitals data containing sensitive medical, financial and biometric records linked to more than 12 million people.
hackread.com
July 30, 2026 at 10:40 PM
Daily IT Security Digest — 2026-07-31
exploit behind a breach affecting 12 million customers. NYC Health + Hospitals faces claims from extinction group LeakNet that it stole an 11TB archive affecting 12 million people (1.8M officially confirmed). Exact Sciences disclosed 11.3 million unique email
July 31, 2026 at 5:02 AM
LeakNet Claims 11TB Stolen from NYC Health + Hospitals: Scrutiny Required #CyberSecurity #DataBreach #HealthCare
LeakNet Claims 11TB Stolen from NYC Health + Hospitals: Scrutiny Required
LeakNet claims 11TB stolen from NYC Health + Hospitals. Scrutiny of data integrity and organizational response is essential for accountability.
cybernewsroom.xyz
July 30, 2026 at 3:00 AM
Daily IT Security Digest — 2026-07-30
— 12M Records Claimed

Extortion group LeakNet alleges it stole an 11 terabyte archive from NYC Health + Hospitals containing data affecting up to 12 million people. So far, only 1.8 million victims have been officially confirmed, making the full scope
July 30, 2026 at 5:02 AM