• News/
  • https://www.bleepingcomputer.com/news/security/oneclik-attacks-use-microsoft-clickonce-and-aws-to-target-energy-sector/

Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks

BleepingComputer
·
Ionut Ilascu
·
Published Jun 25, 2025
·
Updated

A sophisticated malicious campaign that researchers call OneClik has been leveraging Microsoft’s ClickOnce software deployment tool and custom Golang backdoors to compromise organizations within the energy, oil, and gas sectors. The hackers rely on legitimate AWS cloud services (AWS, Cloudfront, API Gateway, Lambda) to keep the command and control (C2) infrastructure hidden. ClickOnce is a deployment technology from Microsoft that allows developers to create self-updating Windows-based applications, reducing user interaction to a minimum. Security researchers at cybersecurity company Trellix analyzed three variants of the campaign (v1a, BPI-MDM, and v1d), all of them deploying “a sophisticated Golanguage backdoor” called RunnerBeacon via a .NET-based loader tracked as OneClikNet. According to them, each version of the OneClik campaign evolved with advanced tactics and C2 obfuscation, robust anti-analysis, and sandbox evasion techniques. While operational indicators point to China-affiliated threat actors, the researchers are cautious in making an attribution. OneClik attacks combine legitimate tools with custom malware and cloud and enterprise tooling, which allows the threat actor to evade detection of the operation. It starts with a phishing email with a link to a fake hardware analysis site hosted in the Azure ecosystem that delivers a .APPLICATION file (ClickOnce manifest) disguised as a legitimate tool. Trellix researchers say that the attacker used ClickOnce apps as a ...

Read full article

Affected Software

2 affected components
Microsoft ClickOnce
Trellix OneClikNet
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a malicious campaign named OneClik that targets organizations in the energy sector using Microsoft ClickOnce and AWS services.

2

What security implications are discussed in the article?

The article outlines the stealthy nature of the OneClik attacks and highlights how they exploit vulnerabilities in Microsoft ClickOnce to deploy malicious Golang backdoors.

3

What sectors are primarily targeted by the OneClik attacks?

The OneClik attacks primarily target organizations within the energy, oil, and gas sectors.

4

What software is affected by the OneClik campaign?

The affected software includes Microsoft ClickOnce and Trellix OneClikNet.

5

What tools do hackers utilize in the OneClik attacks?

Hackers use Microsoft ClickOnce as a deployment tool and custom Golang backdoors to compromise targeted organizations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203