Documentation placeholder domain used in ClickFix attacks
Placeholder domain third-party.com is serving ClickFix lures that execute remote PowerShell on Windows.
Manifold Security found that third-party.com, a domain commonly used as a documentation placeholder, is serving a ClickFix lure to Windows users. The page mimics a Cloudflare human check, poisons the clipboard, and tells victims to press Win+R and paste a command that pulls and runs a remote PowerShell payload. ESET reported ClickFix detections rose 108 percent between late 2025 and early 2026. The domain was reported to registrar Network Solutions, but the lure was still described as active.
- third-party.com is an unreserved documentation placeholder now serving malware
- A fake Cloudflare check poisons the clipboard and prompts Win+R
- The pasted command downloads and runs remote PowerShell
- ESET reported ClickFix detections rose 108 percent into early 2026
- The domain was reported to Network Solutions but remained risky
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | third-party.com | The domain name third-party[.]com is being used to serve malware to users — bad news for th |
Full article309 words · extracted from csoonline.com · click to collapse
The domain name third-party[.]com is being used to serve malware to users — bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party domain. The site is serving a ClickFix lure to Windows machines, which sidesteps existing protection and can effect changes to PowerShell, according to Manifold Security, which discovered the problem.
It’s an interesting site to target. Web developers frequently use the third-party[.]com domain as a stand-in for another website in code or documentation, so the malware poses a serious risk to enterprises who may be inadvertently sending employees or customers to the malicious site.
A more familiar placeholder domain is example.com — but this, like example.org and a handful of others, is reserved by IANA, the Internet Assigned Numbers Authority, so no-one can register it.
The domain at issue here is not reserved in this way, which means that anyone can register it and, as Manifold wryly points out, someone did.
The malware operates by mimicking a Cloudflare “are you human?” check, poisoning the clipboard, and telling the user to press Win+R and paste. The pasted command pulls and runs a remote PowerShell payload on the user’s machine, without being detected.
The ClickFix attack is not new; bad actors have been using it with various lures for a couple of years now, with third-party[.]com just the latest. The latest ESET Security Threat report noted that ClickFix detections rose by 108 percent between the latter half of 2025 and the first half of 2026, follows a 517 percent jump in the previous report, so it’s an attack method very much on the rise.
Following Manifold’s discovery, the third-party[.]com domain has now been reported to its registrar, Network Solutions. But the threat is still present, waiting to catch unwary visitors, so let that be an example.com to you.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.csoonline.com/article/4226782/documentation-placeholder-domain-used-in-clickfix-attacks.html