ClickFix and PySoxy Proxying Threatens Cybersecurity with Enhanced Persistence

ClickFix and PySoxy Proxying Threatens Cybersecurity with Enhanced Persistence

First seen 13 May 2026, 12:23 UTC Infosecurity-MagazineGbhackersCsoonlineSocprime 87% similarity 69.0

Article Content

Browse articles
ThreatCluster

Cybercriminals are leveraging ClickFix attacks in combination with the PySoxy proxy tool to maintain persistence on compromised systems. This tactic allows attackers to bypass traditional defenses and continue their operations even after initial access is blocked. The campaign, reported by ReliaQuest, indicates a shift from one-time exploits to modular post-exploitation strategies. Attackers use social engineering to trick victims into executing malicious commands, which then establish multiple command-and-control (C2) channels. The use of PySoxy enables encrypted proxy access, complicating detection and response efforts. This evolution in tactics poses significant challenges for cybersecurity teams, as it requires a more comprehensive approach to incident response. The Australian Cyber Security Centre recently issued warnings about widespread ClickFix campaigns targeting various organizations. Security professionals are advised to review scheduled tasks and analyze Python artifacts to mitigate these threats.

Key Points: • ClickFix attacks are evolving to include PySoxy for enhanced persistence. • Attackers use social engineering to trick victims into executing malicious commands. • Cybersecurity teams must adopt comprehensive incident response strategies to counter these threats.

ThreatCluster AI

Timeline

2026-04-01
ClickFix attack campaign observed
ReliaQuest reported a campaign using ClickFix to establish initial access via social engineering.
Csoonline
2026-05-12
ReliaQuest details ClickFix and PySoxy combination
Researchers highlighted the use of PySoxy for maintaining persistence in ClickFix attacks, complicating containment efforts.
Infosecurity-Magazine
2026-05-13
Australian Cyber Security Centre issues warning
ACSC warned about widespread ClickFix campaigns targeting infrastructure providers and other organizations.
Infosecurity-Magazine

Community

Browse all →