people · May 17, 2026
ReliaQuest Identifies ClickFix Attack Chain Using PySoxy Proxy
Share the canonical public link.
ReliaQuest Threat Research Team identified a ClickFix attack chain using PySoxy proxy on May 14, 2026. The attack evolved from user-run delivery to a modular post-exploitation chain with a second encrypted C2 path via PySoxy proxy for persistent multi-stage access. ReliaQuest detailed how the operator used scheduled tasks and PySoxy to outlive blocked connections and demanded full artifact removal for persistence. Cyber_OSINT shared the ReliaQuest report on X with 14 likes and 4 reposts on May 14, 2026.
Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)