ReliaQuest researchers observed a new ClickFix attack chain that pairs the social engineering technique with PySoxy, a decade-old open-source Python proxy tool, to establish redundant encrypted C2 access paths. The attack begins with a ClickFix lure tricking victims into executing a malicious command, which then sets up persistence via scheduled tasks, performs domain reconnaissance, opens a PowerShell-based C2 channel, and deploys PySoxy as a second encrypted communication path. This dual-channel approach ensures the intrusion continues even if the primary PowerShell C2 is blocked. Defenders are advised to hunt for scheduled task anomalies, unusual Python artifacts, and proxy-style command-line flags like -ssl, -remote_ip, and SOCKS.

3m read timeFrom csoonline.com
Post cover image
210 Impressions