The cybersecurity community has witnessed the rapid emergence of a new phishing kit that automates the creation of “ClickFix” attack pages, allowing malicious users with minimal technical expertise to deploy advanced deception engines.
See also: Clickfix attack promises “Free WiFi” but distributes malware

Called IUAM ClickFix Generator , it bundles all the necessary configuration options—page title, domain, verification prompts, and clipboard instructions—into a web interface. The result is a ready-to-use solution that creates malicious pages that pretend to be legitimate browser verification challenges, tricking victims into executing commands that install malware.
It was first observed in early July 2025, with the first samples of the ClickFix Generator appearing on underground forums promoting phishing-as-a-service. Campaign reports indicate that attackers exploited compromised domains as hosting environments, injecting encrypted JavaScript into existing web pages to deliver phishing overlays seamlessly. These pages typically mimic Cloudflare-style verification checks, instructing users to copy and paste commands into system consoles under the guise of proving they are human.
See also: From MostereRAT to ClickFix: New malware campaigns

While social engineering has long been a staple of phishing, the ClickFix approach weaponizes manual user actions as the primary infection vector, bypassing automated security measures at the network and endpoint levels. Analysts noted that despite variations in dozens of observed domains, all phishing pages share a nearly identical HTML structure and JavaScript that intercept click events to copy malicious commands to the victim's clipboard.
Some variants include rudimentary operating system detection logic—parsing navigator.userAgent—to tailor instructions for Windows or macOS systems, while others present uniform instructions that work on any desktop platform. Actual campaigns have delivered the DeerStealer infostealer to Windows systems and the Odyssey macOS infostealer via Base64-encoded shell commands.
The operational impact of these campaigns is significant. By offloading execution to the victim, attackers avoid content inspection engines and browser sandboxes that would normally block automated payload downloads. Organizations have reported multiple incident response failures in which victims inadvertently executed multi-stage batch or shell scripts, resulting in credential theft and persistent backdoors.
See also: Lazarus APT uses ClickFix technique to steal data

The lower barrier to entry offered by ClickFix Generator threatens to expand the pool of actors capable of launching targeted phishing campaigns against businesses and public sector targets.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
