{"id":9590,"date":"2026-09-25T16:42:48","date_gmt":"2026-09-25T16:42:48","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9590"},"modified":"2026-09-25T16:42:48","modified_gmt":"2026-09-25T16:42:48","slug":"documentation-placeholder-domain-used-in-clickfix-attacks","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9590","title":{"rendered":"Documentation placeholder domain used in ClickFix attacks"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">The domain name third-party[.]com is being used to serve malware to users \u2014 bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party domain. The site is serving a ClickFix lure to Windows machines, which sidesteps existing protection and can effect changes to PowerShell, according to Manifold Security, which discovered the problem.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s an interesting site to target. Web developers frequently use the third-party[.]com domain as a stand-in for another website in code or documentation, so the malware poses a serious risk to enterprises who may be inadvertently sending employees or customers to the malicious site.<\/p>\n<p class=\"wp-block-paragraph\">A more familiar placeholder domain is example.com \u2014 but this, like example.org and a handful of others, is <a href=\"https:\/\/www.iana.org\/domains\/reserved\" target=\"_blank\" rel=\"noopener\">reserved by IANA<\/a>, the Internet Assigned Numbers Authority, so no-one can register it.<\/p>\n<p class=\"wp-block-paragraph\">The domain at issue here is not reserved in this way, which means that anyone can register it and, as Manifold wryly points out, someone did.<\/p>\n<p class=\"wp-block-paragraph\">The malware operates by mimicking a Cloudflare \u201care you human?\u201d check, poisoning the clipboard, and telling the user to press Win+R and paste. The pasted command pulls and runs a remote PowerShell payload on the user\u2019s machine, without being detected.<\/p>\n<p class=\"wp-block-paragraph\">The ClickFix attack is not new; <a href=\"https:\/\/www.csoonline.com\/article\/3610611\/rising-clickfix-malware-distribution-trick-puts-powershell-it-policies-on-notice.html\">bad actors have been using it with various lures<\/a> for a couple of years now, with third-party[.]com just the latest. The <a href=\"https:\/\/www.eset.com\/uk\/business\/threat-report\/?srsltid=AU7gw4WKWH06iV965QOu0A2mYVGmTPXPCN6gFnOMRXW4o-AQjPRp2N8M\" target=\"_blank\" rel=\"noopener\">latest ESET Security Threat report<\/a> noted that ClickFix detections rose by 108 percent between the latter half of 2025 and the first half of 2026, follows a 517 percent jump in the previous report, so it\u2019s an attack method very much on the rise.<\/p>\n<p class=\"wp-block-paragraph\">Following Manifold\u2019s discovery, the third-party[.]com domain has now been reported to its registrar, Network Solutions. But the threat is still present, waiting to catch unwary visitors, so let that be an example.com to you.<\/p>\n<p class=\"wp-block-paragraph\">\n<\/p><\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The domain name third-party[.]com is being used to serve malware to users \u2014 bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party domain. The site is serving a ClickFix lure to Windows machines, which sidesteps existing protection and can effect changes to PowerShell, according [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9591,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9590","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9590"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9590"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9590\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9591"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9590"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9590"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9590"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}