OneClik Cyber Espionage: The New Weapon Targeting Oil, Gas, and Energy Sectors

Listen to this Post

Featured Image

A Stealthy Threat Looms Over Critical Industries

A disturbing new wave of cyberattacks is targeting vital infrastructure sectors, including energy, oil, and gas. Dubbed OneClik, this advanced campaign employs Microsoft’s ClickOnce deployment technology and stealthy Golang backdoors to infiltrate systems, compromise data, and maintain persistent access. Cybersecurity experts at Trellix reveal that this operation exhibits hallmarks of Chinese-affiliated threat actors, though definitive attribution remains inconclusive.

What makes this threat especially insidious is its use of legitimate enterprise tools in ways that evade traditional security systems, reflecting a broader evolution in attack strategies. By mimicking trustworthy software deployment methods and leveraging cloud environments like AWS, OneClik is a chilling reminder that attackers are not just becoming more advanced — they’re becoming nearly invisible.

The Anatomy of the OneClik Attack 🧬

Researchers have uncovered that the OneClik campaign initiates through phishing emails containing links to deceptive hardware analysis websites. Once clicked, these links deploy ClickOnce applications — a Microsoft technology designed to simplify app installations — which execute malicious code via the legitimate Windows binary dfsvc.exe.

This .NET-based loader, OneClikNet, is responsible for delivering a sophisticated backdoor written in Go, known as RunnerBeacon. This implant connects with command-and-control (C2) infrastructure concealed within Amazon Web Services, leveraging several communication protocols: HTTP(s), WebSockets, raw TCP, and SMB named pipes.

RunnerBeacon offers a full suite of espionage tools, including:

File manipulation

Process enumeration and termination

Shell command execution

Privilege escalation through token theft

Lateral movement

Proxy and network routing via SOCKS5

To remain undetected, it integrates anti-analysis mechanisms and mimics other known malware strains like Geacon, suggesting it may be a custom fork tailored for stealthy operations in cloud environments.

A Surge in Variants and Global Reach 🌍

In March 2025 alone, three variants of OneClik (v1a, BPI-MDM, and v1d) were observed, each demonstrating enhanced evasion capabilities. A previous version of RunnerBeacon was detected in the Middle East’s oil sector as early as September 2023.

Meanwhile, APT-Q-14, a threat actor linked to Northeast Asia, has also adopted ClickOnce tactics. This group exploited a zero-day XSS vulnerability in a webmail platform to stealthily deliver malware through phishing emails disguised as Yahoo News. Victims unknowingly downloaded a trojan that exfiltrated sensitive system data and enabled further intrusion.

APT-Q-14 has affiliations with groups like APT-Q-12 (Pseudo Hunter) and APT-Q-15, all believed to be subsets of the DarkHotel (APT-C-06) cyber-espionage syndicate. This same group recently used a BYOVD (Bring Your Own Vulnerable Driver) technique to bypass Microsoft Defender and deploy malware via fake MSI installers.

What Undercode Say: 🧠 Cyber Intelligence Deep Dive

A Shift Toward Sophisticated Stealth

Undercode’s analysis confirms that OneClik represents a shift from brute-force exploitation to subtle infiltration. By blending into the fabric of enterprise systems and exploiting trusted Windows components, the threat actors are minimizing visibility while maximizing impact.

The use of ClickOnce, particularly through dfsvc.exe, signifies a strategic move to hijack the trust mechanisms of software deployment. Since these applications require no administrative privileges, attackers can infiltrate without triggering standard defenses. This is a classic “living off the land” (LotL) tactic — using built-in tools against the system itself.

Cloud Infrastructure as a Double-Edged Sword

The abuse of AWS infrastructure to host C2 servers illustrates how cloud services are being turned into command centers for malware operations. These platforms, designed for scalability and speed, inadvertently help attackers remain agile and anonymous. Security systems must now pivot from perimeter-focused strategies to cloud-aware threat detection.

The Golang Threat Evolution

RunnerBeacon’s foundation in Golang is no accident. Go binaries are cross-platform, fast, and often less scrutinized by traditional AV systems. Its codebase mirrors the capabilities of Geacon, the Go-based Cobalt Strike alternative, making it a dangerous evolution with modular design and flexible C2 routing.

Growing Ecosystem of APT Activity

From APT-Q-14 to DarkHotel (APT-C-06), this campaign exists within a broader ecosystem of espionage-driven cybercrime. These threat groups share tools, techniques, and even codebases. The lines between state-backed actors and cybercriminal syndicates are blurring, and their targets — often related to national interests — are high-value and geopolitically significant.

Implications for Critical Infrastructure

The focus on energy, oil, and gas sectors underlines the strategic intent of the campaign. Disruption or data theft in these industries could have ripple effects across global economies. The adaptability of OneClik means it can easily pivot toward financial institutions, government agencies, or telecom networks.

✅ Fact Checker Results

ClickOnce abuse confirmed: Documented by Trellix and aligned with MITRE ATT\&CK.

RunnerBeacon’s similarity to Geacon: Validated through technical comparison.

APT-Q-14 links to DarkHotel: Cited by QiAnXin and 360 Threat Intelligence Center.

🔮 Prediction: What Comes Next in the OneClik Campaign?

Increased use of cloud-native malware will make detection even harder for traditional AV and EDR tools.
More variants of OneClik are likely to emerge, possibly targeting other industries like defense or telecom.
Expect greater collaboration between threat groups, blurring attribution lines and complicating countermeasures.

Organizations must evolve their cybersecurity strategies beyond perimeter defense, incorporating behavioral analytics, zero-trust principles, and active threat hunting — or risk falling prey to the next wave of invisible, unstoppable cyberattacks.

References:

Reported By: thehackernews.com
Extra Source Hub:
https://www.quora.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 Telegram