logo

ClickFix Evolves with 10-Year-Old Open-Source Python SOCKS5 Proxy

ID: 4bbbbd4a-6b63-5797-8174-6bc571298b3f

STIX ID: report--4bbbbd4a-6b63-5797-8174-6bc571298b3f

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-13

Date Updated: 2026-05-14

Author: Tushar Subhra Dutta

...
...

A ClickFix campaign is described where attackers use a fake prompt to get users to paste-and-run PowerShell, then deploy a scheduled task and a staged script in C:\ProgramData to maintain persistence and reconnaissance; they also introduce PySoxy (a Python SOCKS5 proxy) as a second independent access channel. The report warns that blocking a single outbound connection is insufficient, recommends full host isolation, removal of staged scripts/Python bytecode, and hunting for scheduled tasks and proxy-style Python execution, and provides IP and domain IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.