A sophisticated malicious campaign that researchers call OneClik has been leveraging Microsoft’s ClickOnce software deployment tool and custom Golang backdoors to compromise organizations within the energy, oil, and gas sectors. The hackers rely on legitimate AWS cloud services (AWS, Cloudfront, API Gateway, Lambda) to keep the command and control (C2) infrastructure hidden. ClickOnce is a deployment technology from Microsoft that allows developers to create self-updating Windows-based applications, reducing user interaction to a minimum. Security researchers at cybersecurity company Trellix analyzed three variants of the campaign (v1a, BPI-MDM, and v1d), all of them deploying “a sophisticated Golanguage backdoor” called RunnerBeacon via a .NET-based loader tracked as OneClikNet. According to them, each version of the OneClik campaign evolved with advanced tactics and C2 obfuscation, robust anti-analysis, and sandbox evasion techniques. While operational indicators point to China-affiliated threat actors, the researchers are cautious in making an attribution. OneClik attacks combine legitimate tools with custom malware and cloud and enterprise tooling, which allows the threat actor to evade detection of the operation. It starts with a phishing email with a link to a fake hardware analysis site hosted in the Azure ecosystem that delivers a .APPLICATION file (ClickOnce manifest) disguised as a legitimate tool. Trellix researchers say that the attacker used ClickOnce apps as a ...
Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks
BleepingComputer
·Ionut Ilascu
·Published Jun 25, 2025
·Updated
Affected Software
2 affected components
Microsoft ClickOnce
Trellix OneClikNet
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a malicious campaign named OneClik that targets organizations in the energy sector using Microsoft ClickOnce and AWS services.
2
What security implications are discussed in the article?
The article outlines the stealthy nature of the OneClik attacks and highlights how they exploit vulnerabilities in Microsoft ClickOnce to deploy malicious Golang backdoors.
3
What sectors are primarily targeted by the OneClik attacks?
The OneClik attacks primarily target organizations within the energy, oil, and gas sectors.
4
What software is affected by the OneClik campaign?
The affected software includes Microsoft ClickOnce and Trellix OneClikNet.
5
What tools do hackers utilize in the OneClik attacks?
Hackers use Microsoft ClickOnce as a deployment tool and custom Golang backdoors to compromise targeted organizations.