ClickFix Evolves Using Decade-Old Open-Source Python SOCKS5 Proxy
ID: 836999a5-19d4-515a-8342-3d7fa0153528
STIX ID: report--836999a5-19d4-515a-8342-3d7fa0153528
Feed Name: GBHackers
ReliaQuest observed a ClickFix campaign that moves beyond single-step user-triggered infections by installing a scheduled-task persistent PowerShell stager that runs an in-memory RAT for reconnaissance and command execution, then deploying PySoxy (a Python SOCKS5 proxy) to create an encrypted secondary C2 over port 443. The report includes observed command lines, persistence details, reconnaissance actions, IOCs (IPs and domains), and detection/containment recommendations emphasizing system isolation and scheduled-task and ProgramData artifact reviews.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
