
OneClik: ClickOnce + AppDomainManager Injection with ETW Patching and AWS-Hidden C2
A ClickOnce-delivered intrusion at an oil-and-gas operator that mirrors nation-state tradecraft. A spearphishing link served a Microsoft ClickOnce deployment that ran under the trusted dfsvc.exe, sideloaded a signed binary whose tampered .config used .NET AppDomainManager hijacking to load an attacker assembly at CLR startup, patched Event Tracing for Windows to blind the sensor, ran anti-debugging checks, and injected a Golang backdoor (RunnerBeacon) that hid its C2 behind AWS CloudFront and API Gateway. Reconstruct the chain from email, endpoint XDR, and cloud audit telemetry, and classify the key ATT&CK techniques.
Launches in 4 days
Tuesday, August 11, 2026 at 9:00 AM
Pro unlocks this operation at launch.
Training Tools
What you'll investigate
8 objectives unlock when this operation goes live.
Be first when it launches
Create your account and grab Pro before launch. The moment this operation goes live on Aug 11, 2026, you can jump straight in.
Get Started Free