LeakNet is a ransomware and data-extortion operation first observed in late 2024. Its campaigns use opportunistic initial access rather than a narrowly defined victim profile. The group has threatened to disclose alleged stolen data from NYC Health + Hospitals, demonstrating targeting of the United States healthcare sector; the claimed volume of stolen data and number of affected individuals remain unverified. LeakNet uses ClickFix social engineering on compromised legitimate websites, including counterfeit Cloudflare Turnstile verification prompts that induce users to execute malicious Windows Installer commands. Its delivery chain uses PowerShell and Visual Basic Script to launch a loader built on the legitimate Deno runtime. The loader executes base64-encoded JavaScript largely in memory, minimizes disk artifacts, fingerprints compromised systems, and repeatedly retrieves and executes additional payloads. Confirmed intrusions exhibit a consistent post-exploitation sequence involving DLL sideloading through a legitimate Java process, Kerberos ticket enumeration, and PsExec-based lateral movement. LeakNet also uses Amazon S3 and other trusted cloud services for payload staging and exfiltration. Its adoption of self-directed ClickFix delivery reduces dependence on initial access brokers. The group's country of origin and any state affiliation are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
28 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data-extortion operation claiming theft of a large archive from NYC Health + Hospitals and threatening further releases of allegedly stolen sensitive patient and internal data.
Data-extortion operation claiming theft of 11TB of data from NYC Health + Hospitals and threatening to publish the remaining material.
The post claims that Leaknet published data related to Far East Horizon Limited, describing it as a 'full database leak.' The entry is sparse and provides no technical details on data volume, attack method, ransom demand, or deadline.
A post attributed to the leaknet ransomware/extortion operation claims a breach of Ktunaxa Nation Council and indicates that data has been published. The post provides only minimal detail, with no stated data volume, ransom demand, deadline, or technical intrusion specifics.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.