Campaign record
IUAM ClickFix Generator
IUAM ClickFix Generator, a builder kit for fake browser-verification lures
- Status as last assessed
- Active
- First seen
- 2025-07-18
- Last seen
- Unrecorded
- Indicators
- 1
- Sources
- 1
- Targets
- Cross-platform
- Fake browser verification challenge
- IUAM ClickFix Generator
- Phishing kit builder
Original research
- Unit 42, Palo Alto Networks2025-10-08Vendor researchFirst account
The ClickFix Factory: First Exposure of IUAM ClickFix Generator
This page summarises and structures that research; it is not a substitute for the original.
Researchers: if anything here misrepresents your work, email corrections@clickfixreport.com — we correct within 5 working days, no questions asked.
Summary
Unit 42 found the builder rather than only its output. An open HTTP server on TCP port 3000 ran an Express web application, styled with Tailwind, whose single job was producing counterfeit browser-verification pages. An operator fills in a form: page title, spoofed domain, the wording of the widget, footer and instruction panel, and above all the string that gets placed silently into a visitor's clipboard. Further options cover obfuscation, automatic clipboard-copy injection, a prompt telling phone users to move to a computer, and detection of the visitor's platform so Windows sees one instruction and macOS another. The host was reachable from mid-July 2025 into early October. Unit 42 treats the find as evidence of commoditisation: rival kits competing to package the technique for buyers who lack the skill to write one.
Execution mechanisms
The only execution mechanism any published account describes for this campaign is Clipboard injection (T1204.004), which 15 of the 44 published campaigns in this corpus also record (34%).
Indicators
1 indicator, each present verbatim in at least one of the sources above. Values are shown defanged and are not links to the hosts — the link goes to our page for that indicator.
| Indicator | Type | Role | Assessment | First seen | Report an error |
|---|---|---|---|---|---|
| ip, shown defanged for safety: 38 dot 242 dot 212 dot 5 | ip | Other | Attacker-controlled | 2025-07-18 | Report an error in ip record f073bace-b192-4209-88f1-b4b10ad860a1 |
“Assessment” is who controls the host, not how dangerous it is. Many of these are compromised legitimate sites whose owners are victims, and they are excluded from every blocklist file we publish.
Not on this record
This record does not yet carry a second publisher's account, any overlap with another campaign in this corpus or our own re-checks of these indicators. Each appears on this page as its own section once it exists; none of it is inferred.
Cite as
ClickFixReport, “IUAM ClickFix Generator”, campaign ID bef1cd04, retrieved 2026-08-07, snapshot fb0eed7.
https://clickfixreport.com/campaigns/bef1cd04/iuam-clickfix-generator
Published under CC BY 4.0. Reuse it, including commercially, with attribution. The date above is when this record last changed, not when you opened it — the page is a versioned record, so that is the date a reader needs to find what you saw.