INTEL_REPORT
CrowdStrike Blog · published — · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment New Abuse of the ClickOnce Technology: Part 1 | CrowdStrike Blog Featured New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever Jun 18, 2026 New Abuse of the ClickOnce Technology, Part 1: The Inner Workings of ClickOnce Application Deployment Jun 18, 2026 After Executive Order 14409: Next Steps for Securing AI Jun 17, 2026 F…
https://www.crowdstrike.com/en-us/blog/new-abuse-of-the-clickonce-technology-part-one
sha256:55d7440248d82e08665e38d65375da3952d10cd046e5c0649d2285bfb6b0b8ae
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| dfdll.dll |
| Open → |
| domain | publish.htm | Open → |
| domain | myapp.appref | Open → |
| domain | dfshim.dll | Open → |
| domain | dfldll.dll | Open → |