Target Industry
This campaign is currently targeting the energy sector.
Overview
Threat actors are exploiting Microsoft ClickOnce and Amazon Web Services (AWS) to carry out stealthy cyber-attacks. ClickOnce simplifies the installation and updating of Windows applications without requiring administrative privileges. The sophisticated cyberespionage campaign, known as OneClik, targets the energy, oil, and gas sectors through phishing emails.
Impact
The potential impact of OneClik on affected organisations is significant, with risks including sensitive data theft, operational disruptions, and reputational damage. The targeted sectors, particularly energy and critical infrastructure, are vital for national security, making the implications of such attacks far-reaching. Organisations may face financial losses due to downtime and recovery efforts, alongside potential regulatory repercussions.
Exploitation
The OneClik malware is primarily distributed through phishing emails that direct victims to fake ‘hardware analysis’ websites hosted on Azure Blob Storage. These sites deliver malicious ClickOnce manifests, which, when executed, install the malware without requiring elevated privileges. This stealthy approach allows the malware to blend in with legitimate application activities, making detection challenging. The use of trusted cloud services like AWS further complicates the identification of malicious traffic.
Indicators of Compromise
The table below lists some indicators of compromise (IoCs) for OneClik. For more IoCs please see the Trellix website.
| IoC Type | IoC Value | Description |
| SHA-256 Hash | 0b61707d1fc8821a95c899de0304a55d549c7252ca24d5978f0989f9593a79c2 | Go payload in memory (v1d Go backdoor binary “RunnerBeacon”) |
| SHA-256 Hash | f2c6a9eed870d312be3b7c51998c5326fab17e999d0004931ff84b25233bc9b1 | RunnerBeacon payload detected in 2023 |
| SHA-256 Hash | ea38f13b9ef3ce8351f64ad3685d5fa5fb35e507c71002560f12b24b8c8b546b | Legitimate ZSATray binary used in v1a |
| SHA-256 Hash | 8facceb0b15bbf061ae9ebcb3b97980d90d774c035ece434e4653299afc7babc | Legitimate Citrix utility used in BPI-MDM |
| SHA-256 Hash | b3dd3b9e8c999fe0e1273a52288af65e1f0997a587f3aa2f13e2a0e6f4383f22 | Legitimate Imaging Edge Desktop used in v1d |
| URL | hxxps://dyydej4wei7fq.cloudfront[.]net | CloudFront URL for beacon callbacks (v1a) |
| URL | hxxps://b2zei88b61.execute-api.eu-west-2.amazonaws[.]com | AWS API Gateway endpoint (v1a) |
| URL | hxxps://7dqtdjxfycaqhjvc2qmx5js4aq0juygw.lambda-url.us-east-1.on[.]aws | AWS Lambda function URL (v1d) |
Containment, Mitigations & Remediations
To mitigate the threat posed by OneClik, organisations should disable ClickOnce execution for non-approved applications and deploy advanced network monitoring tools capable of inspecting traffic to and from AWS services. Implementing deep packet inspection (DPI) firewalls can help detect encrypted traffic patterns associated with the RunnerBeacon backdoor. Additionally, educating employees about phishing tactics and scrutinizing .NET configuration files are essential steps in remediation
Threat Group
While operational indicators suggest China-affiliated threat actors, researchers are cautious about making a definitive attribution.
Further Information













