Skip to content
ClickFix and PySoxy Proxying Threatens Cybersecurity with Enhanced Persistence

ClickFix and PySoxy Proxying Threatens Cybersecurity with Enhanced Persistence

First seen 13 May 2026, 12:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 14, 2026 at 11:41 UTC
  • ClickFix attacks are evolving to include PySoxy for enhanced persistence.
  • Attackers use social engineering to trick victims into executing malicious commands.
  • Cybersecurity teams must adopt comprehensive incident response strategies to counter these threats.

Cybercriminals are leveraging ClickFix attacks in combination with the PySoxy proxy tool to maintain persistence on compromised systems. This tactic allows attackers to bypass traditional defenses and continue their operations even after initial access is blocked. The campaign, reported by ReliaQuest, indicates a shift from one-time exploits to modular post-exploitation strategies. Attackers use social engineering to trick victims into executing malicious commands, which then establish multiple command-and-control (C2) channels. The use of PySoxy enables encrypted proxy access, complicating detection and response efforts. This evolution in tactics poses significant challenges for cybersecurity teams, as it requires a more comprehensive approach to incident response. The Australian Cyber Security Centre recently issued warnings about widespread ClickFix campaigns targeting various organizations. Security professionals are advised to review scheduled tasks and analyze Python artifacts to mitigate these threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 129d ago How this analysis works

Timeline

2026-04-01
ClickFix attack campaign observed
ReliaQuest reported a campaign using ClickFix to establish initial access via social engineering.
Csoonline
2026-05-12
ReliaQuest details ClickFix and PySoxy combination
Researchers highlighted the use of PySoxy for maintaining persistence in ClickFix attacks, complicating containment efforts.
Infosecurity-Magazine
2026-05-13
Australian Cyber Security Centre issues warning
ACSC warned about widespread ClickFix campaigns targeting infrastructure providers and other organizations.
Infosecurity-Magazine

More articles in this cluster (4)

Following this threat?

Track ClickFix in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed