distribution · May 13, 2026
ReliaQuest Threat Research Details ClickFix and PySoxy Proxy Chains for Persistent Access
Share the canonical public link.
ReliaQuest observed on May 13, 2026, attackers combining ClickFix with PySoxy to create redundant encrypted access in compromised networks. The technique uses a single command for domain enumeration, C2 establishment, and proxy routing, persisting via scheduled tasks for hours. PySoxy enables traffic tunneling through the host, evading standard blocks. Earlier 2026 incidents involved ClickFix alone for 70% of cases, but PySoxy integration appeared in 20% of analyzed intrusions. CSO Online cited ReliaQuest data showing 12 client detections in May 2026.