OneClik Cyberattack Campaign Targets Energy Sector Using Microsoft ClickOnce and AWS episode artwork

EPISODE · Jun 26, 2025 · 1H 18M

OneClik Cyberattack Campaign Targets Energy Sector Using Microsoft ClickOnce and AWS

from Daily Security Review · host Daily Security Review

A sophisticated cyber-espionage campaign named OneClik is actively targeting energy, oil, and gas organizations using a combination of legitimate cloud infrastructure and novel attack techniques. The campaign, attributed to an unknown but likely state-affiliated actor, leverages Microsoft's ClickOnce deployment technology to deliver custom Golang-based malware known as RunnerBeacon. The use of AWS APIs for command-and-control (C2) communications allows OneClik to operate within trusted cloud environments, making detection by traditional tools extremely difficult.The campaign reflects broader trends in critical infrastructure cyber threats — particularly the abuse of legitimate services to “live off the land” and the use of advanced anti-analysis techniques to avoid detection. RunnerBeacon exhibits environment-aware behavior, anti-debugging checks, and is compiled in Golang to evade traditional antivirus scanning. While attribution remains inconclusive, indicators suggest a potential link to China-affiliated actors.This episode explores how OneClik fits into the evolving threat landscape and what defenders should know:How Microsoft’s ClickOnce technology is abused in phishing emails for stealthy malware deploymentThe use of AWS cloud services as a trusted C2 infrastructure to bypass detectionRunnerBeacon’s anti-debugging and sandbox-evasion mechanisms, including RAM and domain checksThe targeting of nuclear and energy facilities as part of broader geopolitical cyber pressureRecent ransomware trends in the energy sector, with attacks up 80% year-over-yearThe rise of Golang malware in cyber campaigns and its impact on defensive toolingThe critical importance of supply chain and credential monitoring in energy networksOneClik underscores a modern cyber warfare model: sophisticated, cloud-native, and evasive. As threat actors move deeper into the supply chains and IT layers of critical infrastructure, defenders must evolve beyond perimeter controls to emphasize behavioral detection, threat attribution, and real-time intelligence. For cybersecurity leaders in energy and utilities, understanding this campaign is essential to preparing for what comes next.

Episode metadata supplied by the publisher feed · Published Jun 26, 2025

Embed this episode

NOW PLAYING

OneClik Cyberattack Campaign Targets Energy Sector Using Microsoft ClickOnce and AWS

0:00 1:18:25

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Daily Security Review?

This episode is 1 hour and 18 minutes long.

When was this Daily Security Review episode published?

This episode was published on June 26, 2025.

Can I download this Daily Security Review episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!