LeakNet is an emerging ransomware and data-extortion threat actor first observed in late 2024. The group has been linked to low-volume but increasing victimization activity and has demonstrated a shift from dependence on initial access brokers toward running its own access operations. LeakNet has used ClickFix-style social engineering delivered through compromised legitimate websites to trick users into manually executing malicious commands, and has also been associated with phishing-driven delivery in at least some observed intrusion attempts. Its delivery chain includes abuse of the legitimate Deno runtime as a bring-your-own-runtime mechanism to execute base64-encoded JavaScript largely in memory, reducing on-disk artifacts and complicating file-based detection. Across confirmed incidents, LeakNet has shown a consistent post-compromise workflow. Observed tradecraft includes in-memory execution, DLL sideloading using a malicious jli.dll alongside a legitimate Java process, host fingerprinting, command-and-control polling for victim-specific follow-on payloads, Kerberos ticket enumeration with klist, lateral movement with PsExec, and payload staging or exfiltration through trusted cloud storage services such as Amazon S3. This consistency provides a recognizable behavioral pattern even when infrastructure changes. LeakNet has also operated as a data-extortion actor, publicly claiming theft of large volumes of sensitive data from victims and threatening further release. One prominent claim involved alleged theft of healthcare data from NYC Health + Hospitals, but the larger scale asserted by the actor has not been independently validated. Separate reporting also links LeakNet to use of the same broader malware-as-a-service ecosystem and Deno-based codebase seen in other campaigns, indicating the group likely leverages shared criminal tooling rather than exclusively bespoke malware. Overall, LeakNet is best characterized as a financially motivated ransomware and extortion operator that combines opportunistic social engineering, stealthy in-memory execution, DLL sideloading, credential and session-adjacent discovery activity, lateral movement, and cloud-backed staging to scale intrusions and prepare for ransomware deployment or data-theft extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data-extortion operation claiming theft of a large archive from NYC Health + Hospitals and threatening further releases of allegedly stolen sensitive patient and internal data.
Data-extortion operation claiming theft of 11TB of data from NYC Health + Hospitals and threatening to publish the remaining material.
Ransomware group mentioned as another tenant using the same shared TAG-150/serialmenot.com codebase, illustrating the platform's multi-tenant nature.
Emerging ransomware operator using compromised legitimate websites for ClickFix lures, Teams-based phishing, and a Deno-based in-memory loader to gain access and execute payloads. Post-compromise activity includes DLL sideloading, C2 beaconing, Kerberos credential enumeration, lateral movement with PsExec, and exfiltration via AWS S3 buckets.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.