216.73.217.22

ClickFix Evolves with PySoxy Proxying

· Published 13/05/2026 16:41 · Modified 14/05/2026 08:39

Export JSON

Essential information

Published
13/05/2026 16:41
Modified
14/05/2026 08:39
Tags
2026-05-13 clickfix domain reconnaissance post-exploitation powershell c2 pysoxy python proxy scheduled task persistence social engineering
Related entities
2 observables, 20 techniques (mitre), 1 malware, 3 others

Description

A sophisticated campaign was observed in April 2026 deploying , a decade-old open-source Python SOCKS5 proxy tool, to establish encrypted proxy access on compromised hosts. The attack chain begins with that tricks users into executing obfuscated PowerShell commands, which then establishes and deploys an in-memory PowerShell-based command-and-control agent. Following activities, attackers deploy to create a redundant encrypted access channel. The persistence mechanism continues attempting re-execution even after initial connections are blocked, demonstrating how single executions can evolve into modular chains. This development represents a significant evolution from simple one-time execution to durable access with multiple redundant pathways, requiring comprehensive remediation beyond blocking initial callbacks.

External references