{"id":16762,"date":"2026-09-25T16:46:10","date_gmt":"2026-09-25T16:46:10","guid":{"rendered":"https:\/\/newestek.com\/?p=16762"},"modified":"2026-09-25T16:46:10","modified_gmt":"2026-09-25T16:46:10","slug":"documentation-placeholder-domain-used-in-clickfix-attacks","status":"publish","type":"post","link":"https:\/\/newestek.com\/?p=16762","title":{"rendered":"Documentation placeholder domain used in ClickFix attacks"},"content":{"rendered":"<div>\n<div id=\"remove_no_follow\">\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<section class=\"wp-block-bigbite-multi-title\">\n<div class=\"container\"><\/div>\n<\/section>\n<p class=\"wp-block-paragraph\">The domain name third-party[.]com is being used to serve malware to users \u2014 bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party domain. The site is serving a ClickFix lure to Windows machines, which sidesteps existing protection and can effect changes to PowerShell, according to Manifold Security, which discovered the problem.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s an interesting site to target. Web developers frequently use the third-party[.]com domain as a stand-in for another website in code or documentation, so the malware poses a serious risk to enterprises who may be inadvertently sending employees or customers to the malicious site.<\/p>\n<p class=\"wp-block-paragraph\">A more familiar placeholder domain is example.com \u2014 but this, like example.org and a handful of others, is <a href=\"https:\/\/www.iana.org\/domains\/reserved\" target=\"_blank\" rel=\"noreferrer noopener\">reserved by IANA<\/a>, the Internet Assigned Numbers Authority, so no-one can register it.<\/p>\n<p class=\"wp-block-paragraph\">The domain at issue here is not reserved in this way, which means that anyone can register it and, as Manifold wryly points out, someone did.<\/p>\n<p class=\"wp-block-paragraph\">The malware operates by mimicking a Cloudflare \u201care you human?\u201d check, poisoning the clipboard, and telling the user to press Win+R and paste. The pasted command pulls and runs a remote PowerShell payload on the user\u2019s machine, without being detected.<\/p>\n<p class=\"wp-block-paragraph\">The ClickFix attack is not new; <a href=\"https:\/\/www.csoonline.com\/article\/3610611\/rising-clickfix-malware-distribution-trick-puts-powershell-it-policies-on-notice.html\">bad actors have been using it with various lures<\/a> for a couple of years now, with third-party[.]com just the latest. The <a href=\"https:\/\/www.eset.com\/uk\/business\/threat-report\/?srsltid=AU7gw4WKWH06iV965QOu0A2mYVGmTPXPCN6gFnOMRXW4o-AQjPRp2N8M\" target=\"_blank\" rel=\"noreferrer noopener\">latest ESET Security Threat report<\/a> noted that ClickFix detections rose by 108 percent between the latter half of 2025 and the first half of 2026, follows a 517 percent jump in the previous report, so it\u2019s an attack method very much on the rise.<\/p>\n<p class=\"wp-block-paragraph\">Following Manifold\u2019s discovery, the third-party[.]com domain has now been reported to its registrar, Network Solutions. But the threat is still present, waiting to catch unwary visitors, so let that be an example.com to you.<\/p>\n<p class=\"wp-block-paragraph\">\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The domain name third-party[.]com is being used to serve malware to users \u2014 bad news for those following a little too literally online documentation that uses it as a placeholder for any third-party domain. The site is serving a ClickFix lure to Windows machines, which sidesteps existing protection and can effect changes to PowerShell, according to Manifold Security, which discovered the problem. It\u2019s an interesting&#8230; <\/p>\n<p class=\"more\"><a class=\"more-link\" href=\"https:\/\/newestek.com\/?p=16762\">Read More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-16762","post","type-post","status-publish","format-standard","hentry","category-uncategorized","is-cat-link-borders-light is-cat-link-rounded"],"_links":{"self":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16762","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16762"}],"version-history":[{"count":0,"href":"https:\/\/newestek.com\/index.php?rest_route=\/wp\/v2\/posts\/16762\/revisions"}],"wp:attachment":[{"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16762"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16762"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newestek.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16762"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}