ClickFix Evolves with PySoxy Proxying
ID: 33213828-23f8-55cc-8dd2-35618f094ee4
STIX ID: report--33213828-23f8-55cc-8dd2-35618f094ee4
Feed Name: ReliaQuest Blog
Threat Score
### Executive summary: ReliaQuest observed a ClickFix campaign where a user-pasted PowerShell command led to scheduled-task persistence, an in-memory PowerShell C2 that polled every three seconds, environment reconnaissance, and the subsequent deployment of PySoxy (a Python SOCKS5 proxy) from ProgramData; the chain created redundant encrypted access paths, and the report provides IOCs and actionable detection and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
