www.malwarebytes.com 25 Sept 2026, 12:42 UTC

Criminals Turn Abandoned Documentation Domain Into a ClickFix Trap

Criminals Turn Abandoned Documentation Domain Into a ClickFix Trap
CyberSIXT Evidence Panel Source marked as original reporting

CRIMINALS have taken control of `third-party[.]com`, a domain commonly used in software documentation, code examples and developer testing, and turned it into a ClickFix trap. Unlike `example.com`, which is reserved for documentation, `third-party[.]com` was an ordinary domain that could be registered. As a result, older documents, tests and skills containing the domain may now direct users towards attacker-controlled infrastructure.

Researchers at Manifold Security found that the domain showed Windows visitors a fake Cloudflare-style verification page. The page attempted to persuade them to open the Windows Run box and paste a command copied to their clipboard. That command was designed to download and execute a PowerShell script. The domain hosting the script was not resolving at the time of the report, so the article does not confirm successful malware deployment.

ClickFix attacks rely on social engineering rather than a malicious attachment or executable download. Fake CAPTCHAs, browser errors, software downloads and support pages tell users to run commands themselves, often using legitimate Windows tools and the user’s own permissions. Potential consequences include information theft and, in organisations, more serious network compromise.

Users should not run commands copied from untrusted websites, emails or messages, and should be particularly suspicious of pages that create urgency or secretly place text on the clipboard.

View full article

Article by CyberSIXT