MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-25 · via InfoWorld

Placeholder domain third-party.com becomes ClickFix malware host

Image via InfoWorld
Image via InfoWorld

Attackers are using third-party[.]com, a domain often used as a placeholder in documentation, to deliver malware. The site serves a ClickFix lure that imitates a Cloudflare check, poisons the clipboard, and instructs users to run a PowerShell payload via Win+R. Manifold Security found the issue and reported the domain to its registrar, but the threat remains.

Expanded Detail

The domain third-party[.]com is not protected like example.com, example.org, and similar names set aside by IANA, so it was available for registration. Manifold Security found it serving a ClickFix lure that fakes a Cloudflare human-verification prompt, alters the clipboard, and directs victims to open Run and paste a command. That command retrieves and executes a remote PowerShell payload.

ClickFix has circulated for roughly two years with different lures. ESET reported detections increased 108% from the second half of 2025 to the first half of 2026, after a 517% rise in its prior report. Manifold alerted Network Solutions, the registrar, yet the site reportedly remains live.

Context

This incident could affect developers, IT teams, and ordinary users who encounter third-party[.]com in copied examples or documentation. Because the domain looks like a harmless placeholder, employees or customers may visit it without suspicion, potentially enabling malware execution on Windows systems. Enterprises may face cleanup costs, disrupted work, and data exposure if such lures succeed. The continued availability of the site may also erode trust in common documentation practices, though the actual harm depends on whether users follow the clipboard instructions.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at InfoWorld →
Related stories
Meta Tightens Muse Safeguards Following Researcher’s Vulnerability Report · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Documentation placeholder domain used in ClickFix attacks.” Browse more stories.