Documentation placeholder domain used in ClickFix attacks
Placeholder domain third-party.com is serving ClickFix lures that execute remote PowerShell on Windows.
Manifold Security found that third-party.com, a domain commonly used as a documentation placeholder, is serving a ClickFix lure to Windows users. The page mimics a Cloudflare human check, poisons the clipboard, and tells victims to press Win+R and paste a command that pulls and runs a remote PowerShell payload. ESET reported ClickFix detections rose 108 percent between late 2025 and early 2026. The domain was reported to registrar Network Solutions, but the lure was still described as active.