s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-6a04a9a171b2ad5ef57d9993 info

📛 Threat Title

ClickFix Evolves with PySoxy Proxying

Category: scheduled task persistence Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

A sophisticated ClickFix campaign was observed in April 2026 deploying PySoxy, a decade-old open-source Python SOCKS5 proxy tool, to establish encrypted proxy access on compromised hosts. The attack chain begins with social engineering that tricks users into executing obfuscated PowerShell commands, which then establishes scheduled task persistence and deploys an in-memory PowerShell-based command-and-control agent. Following domain reconnaissance activities, attackers deploy PySoxy to create a redundant encrypted access channel. The persistence mechanism continues attempting re-execution even after initial connections are blocked, demonstrating how single ClickFix executions can evolve into modular post-exploitation chains. This development represents a significant evolution from simple one-time execution to durable access with multiple redundant pathways, requiring comprehensive remediation beyond blocking initial callbacks. Pulse contains 3 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (6)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 185.205.211.217 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/185.205.211.217

IOC database

Type
ipv4
Value
185.205.211.217
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain overlateise.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/185.205.211.217

domain overlateise.com UrlVoid 1 / 35 1 feed

IOC database

Type
domain
Value
overlateise.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain abledom.net UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
abledom.net
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 206.206.103.106 1 feed

IOC database

Type
ipv4
Value
206.206.103.106
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 206.206.103.120 1 feed

IOC database

Type
ipv4
Value
206.206.103.120
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain strapness.com UrlVoid 1 / 35 1 feed

IOC database

Type
domain
Value
strapness.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • OTX pulse AlienVaulkt OTX

    A sophisticated ClickFix campaign was observed in April 2026 deploying PySoxy, a decade-old open-source Python SOCKS5 proxy tool, to establish encrypted proxy access on compromised hosts. The attack chain begins with social engineering that tricks users into executing obfuscated PowerShell commands, which then establishes scheduled task persistence and deploys an in-memory PowerShell-based command-and-control agent. Following domain reconnaissance activities, attackers deploy PySoxy to create a

  • reference AlienVaulkt OTX

Remediations (8)

  • web:bladeintel.com

    Cybercriminals have combined ClickFix attacks with PySoxy , a 10-year-old open-source Python SOCKS5 proxy, to maintain persistence on victims' machines without malware, even after attempts at removal.

  • web:cyberpress.org

    A simple copy-and-paste script is no longer just a one-time warning it is the gateway to a relentless, multi-layered network invasion. In a recently observed April 2026 intrusion, threat actors deployed a dangerous new combination: pairing the notorious ClickFix social engineering scheme with PySoxy , a decade-old open-source SOCKS5 proxy tool. This evolution transforms a single user mistake ...

  • web:reliaquest.com

    ClickFix just got more dangerous. Discover how one pasted command creates persistent, redundant access—and how to detect it before the damage spreads.

  • web:socprime.com

    ClickFix now chains PowerShell persistence with PySoxy to create encrypted proxy access and harder-to-detect post-compromise control

  • web:vpncentral.com

    A ClickFix attack chain observed by ReliaQuest shows how the social engineering technique is evolving from a one-time user mistake into a more durable intrusion method. In this case, attackers combined malicious PowerShell execution with PySoxy , an open-source Python SOCKS5 proxy tool, to create a second route back into a compromised Windows host. The attack […]

  • web:www.csoonline.com

    ReliaQuest observed attackers pairing ClickFix with the PySoxy proxy tool to establish redundant encrypted access paths and persistence on compromised systems.

  • web:www.cybermaterial.com

    Threat actors have evolved the ClickFix social engineering technique by incorporating PySoxy , a decade-old open-source Python SOCKS5 proxy tool, to establish persistent and covert access to victim networks.

  • web:www.infosecurity-magazine.com

    Cybercriminals have combined ClickFix attacks with PySoxy , a 10-year-old open-source Python SOCKS5 proxy, to maintain persistence on victims' machines without malware, even after attempts at removal. The campaign has been detailed by cybersecurity researchers at ReliaQuest, who warned that it shows that ClickFix attacks are moving beyond one-time user execution into modular post-exploitation ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…