Target Industry

This campaign is currently targeting the energy sector.

Overview

Threat actors are exploiting Microsoft ClickOnce and Amazon Web Services (AWS) to carry out stealthy cyber-attacks. ClickOnce simplifies the installation and updating of Windows applications without requiring administrative privileges. The sophisticated cyberespionage campaign, known as OneClik, targets the energy, oil, and gas sectors through phishing emails. 

Impact

The potential impact of OneClik on affected organisations is significant, with risks including sensitive data theft, operational disruptions, and reputational damage. The targeted sectors, particularly energy and critical infrastructure, are vital for national security, making the implications of such attacks far-reaching. Organisations may face financial losses due to downtime and recovery efforts, alongside potential regulatory repercussions. 

Exploitation

The OneClik malware is primarily distributed through phishing emails that direct victims to fake ‘hardware analysis’ websites hosted on Azure Blob Storage. These sites deliver malicious ClickOnce manifests, which, when executed, install the malware without requiring elevated privileges. This stealthy approach allows the malware to blend in with legitimate application activities, making detection challenging. The use of trusted cloud services like AWS further complicates the identification of malicious traffic. 

Indicators of Compromise

The table below lists some indicators of compromise (IoCs) for OneClik. For more IoCs please see the Trellix website 

IoC Type IoC Value Description 
SHA-256 Hash 0b61707d1fc8821a95c899de0304a55d549c7252ca24d5978f0989f9593a79c2 Go payload in memory (v1d Go backdoor binary “RunnerBeacon”) 
SHA-256 Hash f2c6a9eed870d312be3b7c51998c5326fab17e999d0004931ff84b25233bc9b1 RunnerBeacon payload detected in 2023 
SHA-256 Hash ea38f13b9ef3ce8351f64ad3685d5fa5fb35e507c71002560f12b24b8c8b546b Legitimate ZSATray binary used in v1a 
SHA-256 Hash 8facceb0b15bbf061ae9ebcb3b97980d90d774c035ece434e4653299afc7babc Legitimate Citrix utility used in BPI-MDM 
SHA-256 Hash b3dd3b9e8c999fe0e1273a52288af65e1f0997a587f3aa2f13e2a0e6f4383f22 Legitimate Imaging Edge Desktop used in v1d 
URL hxxps://dyydej4wei7fq.cloudfront[.]net CloudFront URL for beacon callbacks (v1a) 
URL hxxps://b2zei88b61.execute-api.eu-west-2.amazonaws[.]com AWS API Gateway endpoint (v1a) 
URL hxxps://7dqtdjxfycaqhjvc2qmx5js4aq0juygw.lambda-url.us-east-1.on[.]aws AWS Lambda function URL (v1d) 

Containment, Mitigations & Remediations

To mitigate the threat posed by OneClik, organisations should disable ClickOnce execution for non-approved applications and deploy advanced network monitoring tools capable of inspecting traffic to and from AWS services. Implementing deep packet inspection (DPI) firewalls can help detect encrypted traffic patterns associated with the RunnerBeacon backdoor. Additionally, educating employees about phishing tactics and scrutinizing .NET configuration files are essential steps in remediation 

Threat Group

While operational indicators suggest China-affiliated threat actors, researchers are cautious about making a definitive attribution. 

Further Information

SecurityOnline article 

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content