people · May 16, 2026
ReliaQuest Threat Research Details ClickFix Evolution Using PySoxy for Persistent Access
Share the canonical public link.
ReliaQuest Threat Research Team published details on ClickFix attackers deploying PySoxy to enable a second encrypted C2 path via Python tooling downloaded to C:\ProgramData. The technique involved staging reconnaissance output locally, uploading to attacker infrastructure, and executing compiled bytecode identified as PySoxy to turn single-path intrusions into redundant ones. ReliaQuest observed the campaign in April 2026 and highlighted scheduled tasks as a key persistence trigger that relaunched activity after communication failures. ReliaQuest researchers recommended hunting for command lines containing -ssl, -remote_ip, -remote_port, SOCKS, or .pyc execution to detect PySoxy-style activity.