logo

ClickFix Evolves with PySoxy Proxying

ID: 33213828-23f8-55cc-8dd2-35618f094ee4

STIX ID: report--33213828-23f8-55cc-8dd2-35618f094ee4

Feed Name: ReliaQuest Blog

Threat Score
70/100

Date Published: 2026-05-12

Date Updated: 2026-05-13

...
...

### Executive summary: ReliaQuest observed a ClickFix campaign where a user-pasted PowerShell command led to scheduled-task persistence, an in-memory PowerShell C2 that polled every three seconds, environment reconnaissance, and the subsequent deployment of PySoxy (a Python SOCKS5 proxy) from ProgramData; the chain created redundant encrypted access paths, and the report provides IOCs and actionable detection and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.