HomeSecurityNew Phishing Kit automates the ClickFix attack process

New Phishing Kit automates the ClickFix attack process

The cybersecurity community has witnessed the rapid emergence of a new phishing kit that automates the creation of “ClickFix” attack pages, allowing malicious users with minimal technical expertise to deploy advanced deception engines.

See also: Clickfix attack promises “Free WiFi” but distributes malware

ClickFix

Called IUAM ClickFix Generator , it bundles all the necessary configuration options—page title, domain, verification prompts, and clipboard instructions—into a web interface. The result is a ready-to-use solution that creates malicious pages that pretend to be legitimate browser verification challenges, tricking victims into executing commands that install malware.

It was first observed in early July 2025, with the first samples of the ClickFix Generator appearing on underground forums promoting phishing-as-a-service. Campaign reports indicate that attackers exploited compromised domains as hosting environments, injecting encrypted JavaScript into existing web pages to deliver phishing overlays seamlessly. These pages typically mimic Cloudflare-style verification checks, instructing users to copy and paste commands into system consoles under the guise of proving they are human.

See also: From MostereRAT to ClickFix: New malware campaigns

New Phishing Kit automates the ClickFix attack process

While social engineering has long been a staple of phishing, the ClickFix approach weaponizes manual user actions as the primary infection vector, bypassing automated security measures at the network and endpoint levels. Analysts noted that despite variations in dozens of observed domains, all phishing pages share a nearly identical HTML structure and JavaScript that intercept click events to copy malicious commands to the victim's clipboard.

Some variants include rudimentary operating system detection logic—parsing navigator.userAgent—to tailor instructions for Windows or macOS systems, while others present uniform instructions that work on any desktop platform. Actual campaigns have delivered the DeerStealer infostealer to Windows systems and the Odyssey macOS infostealer via Base64-encoded shell commands.

The operational impact of these campaigns is significant. By offloading execution to the victim, attackers avoid content inspection engines and browser sandboxes that would normally block automated payload downloads. Organizations have reported multiple incident response failures in which victims inadvertently executed multi-stage batch or shell scripts, resulting in credential theft and persistent backdoors.

See also: Lazarus APT uses ClickFix technique to steal data

New Phishing Kit automates the ClickFix attack process

The lower barrier to entry offered by ClickFix Generator threatens to expand the pool of actors capable of launching targeted phishing campaigns against businesses and public sector targets.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS