INTEL_REPORT
CrowdStrike Blog · published — · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever New Abuse of the ClickOnce Technology: Part 2 | CrowdStrike Blog Featured New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever Jun 18, 2026 New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment Jun 18, 2026 After Executive Order 14409: Next Steps for Securing AI Jun 17, 202…
https://www.crowdstrike.com/en-us/blog/new-abuse-of-the-clickonce-technology-part-two
sha256:abc07c7a05c655efe1cac0148ac6c3fe4e121ceada58925e3b0f111bdd86ab67
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |
| domain | system.deployment.dll | Open → |
| domain | system.deployement.dll | Open → |
| domain | dfdll.dll | Open → |