Documentation placeholder domain used in ClickFix attacks

The domain name third-party[.]com is being used to serve malware to users — bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party domain. The site is serving a ClickFix lure to Windows machines, which sidesteps existing protection and can effect changes to PowerShell, according to Manifold Security, which discovered the problem.

It’s an interesting site to target. Web developers frequently use the third-party[.]com domain as a stand-in for another website in code or documentation, so the malware poses a serious risk to enterprises who may be inadvertently sending employees or customers to the malicious site.

A more familiar placeholder domain is example.com — but this, like example.org and a handful of others, is reserved by IANA, the Internet Assigned Numbers Authority, so no-one can register it.

The domain at issue here is not reserved in this way, which means that anyone can register it and, as Manifold wryly points out, someone did.

The malware operates by mimicking a Cloudflare “are you human?” check, poisoning the clipboard, and telling the user to press Win+R and paste. The pasted command pulls and runs a remote PowerShell payload on the user’s machine, without being detected.

The ClickFix attack is not new; bad actors have been using it with various lures for a couple of years now, with third-party[.]com just the latest. The latest ESET Security Threat report noted that ClickFix detections rose by 108 percent between the latter half of 2025 and the first half of 2026, follows a 517 percent jump in the previous report, so it’s an attack method very much on the rise.

Following Manifold’s discovery, the third-party[.]com domain has now been reported to its registrar, Network Solutions. But the threat is still present, waiting to catch unwary visitors, so let that be an example.com to you.