Criminals turn placeholder domain into ClickFix trap
Cybersecurity Classified by Officially
A domain that has long appeared in software documentation, code examples, and developer test material is now being used to push a ClickFix attack against Windows users.
A placeholder domain stands in for a website in an example. The best-known is probably example.com. Another, third-party[.]com, has often been used in documentation to represent an external website, API, or service.
However, there is a very important difference between the two: example.com is reserved for documentation, while third-party[.]com is an ordinary domain. Anyone could register it, and someone did. Every document, test, and skill that hardcoded it now points readers and users to the attacker’s infrastructure.
Researchers at Manifold Security found that third-party[.]com was serving a fake Cloudflare-style verification page to Windows visitors. The page tries to persuade them to open the Windows Run box and paste a command it has copied to their clipboard.This command is designed to download and execute a PowerShell script. At the time of writing the domain hosting the script is not resolving.
ClickFix is a social-engineering technique that turns the victim into the malware installer.
Instead of relying on a malicious attachment or an obvious executable download, the attacker convinces someone to run a command themselves. Common lures include:
ClickFix works because the command often uses legitimate Windows or Mac tools to download and execute the next stage. It also runs with the permissions of the person who has been convinced to enter it.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.malwarebytes.com/blog/news/2026/09/criminals-turn-placeholder-domain-into-clickfix-trap
Officially imported this from Malwarebytes’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Malwarebytes — imported from official source
- Official source
- https://www.malwarebytes.com/blog/feed/index.xml RSS
- Imported
- September 25, 2026 13:00
- Versions
- 1 recorded
- Identity
https://www.malwarebytes.com/blog/news/2026/09/criminals-turn-placeholder-domain-into-c...