people · May 18, 2026
ReliaQuest Identifies ClickFix Attack Chain Using PySoxy Proxy Tool
Share the canonical public link.
ReliaQuest identified a ClickFix attack chain using the open-source PySoxy proxy tool on May 14, 2026. Attackers used an obfuscated PowerShell command from a compromised site to create a scheduled task that relaunched every 40 minutes for persistence and established a PowerShell remote access tool polling every three seconds. The chain added reconnaissance via LDAP and SMB plus a secondary encrypted PySoxy SOCKS5 proxy over port 443. ReliaQuest recommended isolating hosts and reviewing scheduled tasks after suspicious PowerShell activity.