Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 17, 2026 (about 4 months ago).

people · May 17, 2026

ReliaQuest Identifies ClickFix Attack Chain Using PySoxy Proxy

Share the canonical public link.

Share as image

ReliaQuest Threat Research Team identified a ClickFix attack chain using PySoxy proxy on May 14, 2026. The attack evolved from user-run delivery to a modular post-exploitation chain with a second encrypted C2 path via PySoxy proxy for persistent multi-stage access. ReliaQuest detailed how the operator used scheduled tasks and PySoxy to outlive blocked connections and demanded full artifact removal for persistence. Cyber_OSINT shared the ReliaQuest report on X with 14 likes and 4 reposts on May 14, 2026.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence