Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 18, 2026 (about 4 months ago).

people · May 18, 2026

ReliaQuest Identifies ClickFix Attack Chain Using PySoxy Proxy Tool

Share the canonical public link.

Share as image

ReliaQuest identified a ClickFix attack chain using the open-source PySoxy proxy tool on May 14, 2026. Attackers used an obfuscated PowerShell command from a compromised site to create a scheduled task that relaunched every 40 minutes for persistence and established a PowerShell remote access tool polling every three seconds. The chain added reconnaissance via LDAP and SMB plus a secondary encrypted PySoxy SOCKS5 proxy over port 443. ReliaQuest recommended isolating hosts and reviewing scheduled tasks after suspicious PowerShell activity.

Failed after 3 attempts. Last error: Service unavailable

Supporting evidence