Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 13, 2026 (about 4 months ago).

distribution · May 13, 2026

ReliaQuest Threat Research Details ClickFix and PySoxy Proxy Chains for Persistent Access

Share the canonical public link.

Share as image

ReliaQuest observed on May 13, 2026, attackers combining ClickFix with PySoxy to create redundant encrypted access in compromised networks. The technique uses a single command for domain enumeration, C2 establishment, and proxy routing, persisting via scheduled tasks for hours. PySoxy enables traffic tunneling through the host, evading standard blocks. Earlier 2026 incidents involved ClickFix alone for 70% of cases, but PySoxy integration appeared in 20% of analyzed intrusions. CSO Online cited ReliaQuest data showing 12 client detections in May 2026.

The body justifies a high significance score as it details a specific, named threat technique (ClickFix and PySoxy integration) with clear impact metrics like 70% and 20% usage in intrusions, plus 12 client detections, making it a major development in cybersecurity persistence methods. Information density is strong with verifiable facts including ReliaQuest as the observer, exact date (May 13, 2026), tool names, percentages, and incident counts from CSO Online. Analysis value is zero since the field explicitly states '(none)', providing no strategic insight beyond the headline.

Supporting evidence