ClickFix Evolves with PySoxy Proxying

A sophisticated ClickFix campaign was observed in April 2026 deploying PySoxy, a decade-old open-source Python SOCKS5 proxy tool, to establish encrypted proxy access on compromised hosts. The attack chain begins with social engineering that tricks users into executing obfuscated PowerShell commands, which then establishes scheduled task persistence and deploys an in-memory PowerShell-based command-and-control agent. Following domain reconnaissance activities, attackers deploy PySoxy to create a redundant encrypted access channel. The persistence mechanism continues attempting re-execution even after initial connections are blocked, demonstrating how single ClickFix executions can evolve into modular post-exploitation chains. This development represents a significant evolution from simple one-time execution to durable access with multiple redundant pathways, requiring comprehensive remediation beyond blocking initial callbacks.

Pulse ID: 6a04a9a171b2ad5ef57d9993
Pulse Link: https://otx.alienvault.com/pulse/6a04a9a171b2ad5ef57d9993
Pulse Author: AlienVault
Created: 2026-05-13 16:41:05

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #InfoSec #OTX #OpenThreatExchange #PowerShell #Proxy #Python #RAT #RCE #SocialEngineering #bot #socks5 #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
Space Junk: The Captain
She has a massive payday waiting at the finish line, if the ship doesn't fall apart first. Meet the captain.

#CyberSecurity #PowerShell #CFML #AI #Networking #SQL #Cloud #GRC #Gaming #Technology #Python #ZeroTrust #DevSecOps #FinOps #Programming

Game Link: https://blackcatwhitehatsecurity.com/theGame4.cfm
Big update to my PSClock module. Added commands to display a clock in a corner of the console or a clock in the session title bar. Install or update from the #PowerShell Gallery. https://github.com/jdhitsolutions/PSClock
Raimund Andree will be on stage for #PSConfEU 2026 in #Wiesbaden (1-4 June)! πŸŽ™οΈ Reverse AI-ngineering πŸŽ™οΈ PowerShell + Proxmox: Open-Source Virtualization Unleashed 🎟️ Book your tickets for the #PowerShell #Conference #Europe in #Germany: psconf.eu #automation #IT
The Game III: The Incinerator
Legacy syntax is the only thing standing between you and the next level. Are your CF skills sharp enough or will you end up in the Incinerator?

#CyberSecurity #PowerShell #CFML #AI #Networking #SQL #Cloud #GRC #Gaming #Technology #Python #ZeroTrust #DevSecOps #FinOps #Programming

Game Link: https://blackcatwhitehatsecurity.com/theGame3.cfm

why is it `resolve-dnsname` and not `get-dnsname` ?

I mean the oddball verb seems pointless to me

#powershell #justGrumbling

Part 2 of my graceful reboot series - a real-world use case: pushing Microsoft's 2026 Secure Boot certificate update via Intune Remediations, with a user-friendly reboot built in.

http://dlvr.it/TSWSCn

#Intune #SecureBoot #PowerShell

Feeling lost in your #tech #career? 🎯 @[email protected]’s talk at #PSConfEU is a guide to finding your North Star goal – your long-term why. πŸ’¬ Purpose, visibility, networks & focus – all in one session. 🎟️ #PSConfEU 2026 in Wiesbaden: psconf.eu #PowerShell

- YouTube
Home - PSConfEU

Discover PowerShell scripting & automation at psconf.eu. Join experts, learn, & boost productivity. Elevate your skills today!

PSConfEU
Can't always blame AI for the RAMpocalypse! One day I'll learn to write efficient PowerShell, but until then....
#PowerShell