Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 16, 2026 (about 4 months ago).

people · May 16, 2026

ReliaQuest Threat Research Details ClickFix Evolution Using PySoxy for Persistent Access

Share the canonical public link.

Share as image

ReliaQuest Threat Research Team published details on ClickFix attackers deploying PySoxy to enable a second encrypted C2 path via Python tooling downloaded to C:\ProgramData. The technique involved staging reconnaissance output locally, uploading to attacker infrastructure, and executing compiled bytecode identified as PySoxy to turn single-path intrusions into redundant ones. ReliaQuest observed the campaign in April 2026 and highlighted scheduled tasks as a key persistence trigger that relaunched activity after communication failures. ReliaQuest researchers recommended hunting for command lines containing -ssl, -remote_ip, -remote_port, SOCKS, or .pyc execution to detect PySoxy-style activity.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence