Skip to content
Threat Feed

Tag

Clickonce

4 briefs RSS
high advisory

Understanding ClickOnce Technology Abuse: Part 1

Threat actors are abusing Microsoft's ClickOnce deployment technology to spread malware, allowing malicious applications to be deployed easily with minimal user interaction and without requiring administrative privileges, ultimately delivering malicious payloads onto user endpoints.

ClickOnce technology +4 clickonce malware-delivery windows endpoint
2t updated
high advisory

New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

Threat actors are actively exploiting Microsoft's ClickOnce deployment technology, leveraging its low user interaction, lack of privilege requirements, and built-in update mechanisms to deliver malware, establish persistence, and maintain remote access, often executing payloads within legitimate rundll32.exe and dfsvc.exe processes.

PoC ClickOnce +11 microsoft persistence delivery windows endpoint
2r 7t 26i updated
medium advisory

New Abuse of ClickOnce Technology: Understanding Internals

CrowdStrike details the internal mechanisms of Microsoft's ClickOnce technology, a legitimate software deployment method that offers minimal user interaction and no administrative privilege requirements, making it a double-edged sword with significant potential for threat actor abuse in malware distribution and persistence.

.NET Framework +1 clickonce windows deployment-technology abuse-of-feature defense-evasion execution
2t
high advisory

New Abuse of ClickOnce Technology: Stop Threat Actors from Clicking Once and Staying Forever

Threat actors are exploiting Microsoft's ClickOnce technology to achieve initial access, execute malicious payloads, and maintain persistence. This abuse leverages ClickOnce's user-friendly deployment, minimal privilege requirements, and built-in update mechanism to bypass traditional security defenses and execute malware stealthily within legitimate Microsoft processes like rundll32.exe. Adversaries achieve persistence by pushing malicious updates, or by placing ClickOnce shortcut files (.appref-ms) in the Windows Startup folder or configuring them as scheduled tasks.

ClickOnce +2 persistence initial-access defense-evasion remote-access microsoft windows
2r 5t