Skip to content
Threat Feed

Product

ClickOnce

4 briefs RSS
high advisory

Autonomous AI Agents Pose New Supply Chain and Data Exfiltration Risks

This content introduces AI Detection and Response (AIDR) as a new cybersecurity category to address emerging threats from autonomous AI agents, including supply chain attacks and unintended data sharing, highlighting their ability to execute with inherited privileges across endpoints, SaaS, and cloud environments.

ClawHub +42 ai agentic-ai aidr supply-chain-attack data-exfiltration cloud-security endpoint-security saas-security
4t 16i updated
high advisory

Understanding ClickOnce Technology Abuse: Part 1

Threat actors are abusing Microsoft's ClickOnce deployment technology to spread malware, allowing malicious applications to be deployed easily with minimal user interaction and without requiring administrative privileges, ultimately delivering malicious payloads onto user endpoints.

ClickOnce technology +4 clickonce malware-delivery windows endpoint
2t updated
high advisory

New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

Threat actors are actively exploiting Microsoft's ClickOnce deployment technology, leveraging its low user interaction, lack of privilege requirements, and built-in update mechanisms to deliver malware, establish persistence, and maintain remote access, often executing payloads within legitimate rundll32.exe and dfsvc.exe processes.

PoC ClickOnce +11 microsoft persistence delivery windows endpoint
2r 7t 26i updated
high advisory

New Abuse of ClickOnce Technology: Stop Threat Actors from Clicking Once and Staying Forever

Threat actors are exploiting Microsoft's ClickOnce technology to achieve initial access, execute malicious payloads, and maintain persistence. This abuse leverages ClickOnce's user-friendly deployment, minimal privilege requirements, and built-in update mechanism to bypass traditional security defenses and execute malware stealthily within legitimate Microsoft processes like rundll32.exe. Adversaries achieve persistence by pushing malicious updates, or by placing ClickOnce shortcut files (.appref-ms) in the Windows Startup folder or configuring them as scheduled tasks.

ClickOnce +2 persistence initial-access defense-evasion remote-access microsoft windows
2r 5t