OTX-6a04a9a171b2ad5ef57d9993
info
📛 Threat Title
ClickFix Evolves with PySoxy Proxying
Description
A sophisticated ClickFix campaign was observed in April 2026 deploying PySoxy, a decade-old open-source Python SOCKS5 proxy tool, to establish encrypted proxy access on compromised hosts. The attack chain begins with social engineering that tricks users into executing obfuscated PowerShell commands, which then establishes scheduled task persistence and deploys an in-memory PowerShell-based command-and-control agent. Following domain reconnaissance activities, attackers deploy PySoxy to create a redundant encrypted access channel. The persistence mechanism continues attempting re-execution even after initial connections are blocked, demonstrating how single ClickFix executions can evolve into modular post-exploitation chains. This development represents a significant evolution from simple one-time execution to durable access with multiple redundant pathways, requiring comprehensive remediation beyond blocking initial callbacks. Pulse contains 3 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (6)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
185.205.211.217
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/185.205.211.217
IOC database
- Type
- ipv4
- Value
185.205.211.217- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain overlateise.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/185.205.211.217
domain
overlateise.com
UrlVoid 1 / 35
1 feed
IOC database
- Type
- domain
- Value
overlateise.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
abledom.net
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
abledom.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
206.206.103.106
1 feed
IOC database
- Type
- ipv4
- Value
206.206.103.106- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
206.206.103.120
1 feed
IOC database
- Type
- ipv4
- Value
206.206.103.120- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
strapness.com
UrlVoid 1 / 35
1 feed
IOC database
- Type
- domain
- Value
strapness.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
-
OTX pulse
AlienVaulkt OTX
A sophisticated ClickFix campaign was observed in April 2026 deploying PySoxy, a decade-old open-source Python SOCKS5 proxy tool, to establish encrypted proxy access on compromised hosts. The attack chain begins with social engineering that tricks users into executing obfuscated PowerShell commands, which then establishes scheduled task persistence and deploys an in-memory PowerShell-based command-and-control agent. Following domain reconnaissance activities, attackers deploy PySoxy to create a
- reference AlienVaulkt OTX
Remediations (8)
-
web:bladeintel.com
Cybercriminals have combined ClickFix attacks with PySoxy , a 10-year-old open-source Python SOCKS5 proxy, to maintain persistence on victims' machines without malware, even after attempts at removal.
-
web:cyberpress.org
A simple copy-and-paste script is no longer just a one-time warning it is the gateway to a relentless, multi-layered network invasion. In a recently observed April 2026 intrusion, threat actors deployed a dangerous new combination: pairing the notorious ClickFix social engineering scheme with PySoxy , a decade-old open-source SOCKS5 proxy tool. This evolution transforms a single user mistake ...
-
web:reliaquest.com
ClickFix just got more dangerous. Discover how one pasted command creates persistent, redundant access—and how to detect it before the damage spreads.
-
web:socprime.com
ClickFix now chains PowerShell persistence with PySoxy to create encrypted proxy access and harder-to-detect post-compromise control
-
web:vpncentral.com
A ClickFix attack chain observed by ReliaQuest shows how the social engineering technique is evolving from a one-time user mistake into a more durable intrusion method. In this case, attackers combined malicious PowerShell execution with PySoxy , an open-source Python SOCKS5 proxy tool, to create a second route back into a compromised Windows host. The attack […]
-
web:www.csoonline.com
ReliaQuest observed attackers pairing ClickFix with the PySoxy proxy tool to establish redundant encrypted access paths and persistence on compromised systems.
-
web:www.cybermaterial.com
Threat actors have evolved the ClickFix social engineering technique by incorporating PySoxy , a decade-old open-source Python SOCKS5 proxy tool, to establish persistent and covert access to victim networks.
-
web:www.infosecurity-magazine.com
Cybercriminals have combined ClickFix attacks with PySoxy , a 10-year-old open-source Python SOCKS5 proxy, to maintain persistence on victims' machines without malware, even after attempts at removal. The campaign has been detailed by cybersecurity researchers at ReliaQuest, who warned that it shows that ClickFix attacks are moving beyond one-time user execution into modular post-exploitation ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.