logo

Hackers Upgrade ClickFix Attacks Using Decade-Old Python SOCKS5 Proxy Tool

ID: 28d1bd83-6008-5282-8780-7432c2079850

STIX ID: report--28d1bd83-6008-5282-8780-7432c2079850

Feed Name: Cyber Press

Threat Score
70/100

Date Published: 2026-05-13

Date Updated: 2026-05-13

Author: Varshini

...
...

ReliaQuest observed an April 2026 intrusion where threat actors used a ClickFix paste-based social-engineering technique to execute a PowerShell RAT that creates a scheduled task for persistence, while also deploying PySoxy (a Python SOCKS5 proxy) to establish a secondary encrypted access path over port 443; defenders must treat such incidents as full compromises, isolate hosts, remove persistence (scheduled tasks and hidden Python runtimes), and investigate provided IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.