Skip to content
Malicious Use of Placeholder Domain Third-Party.com Targets Windows Users

Malicious Use of Placeholder Domain Third-Party.com Targets Windows Users

First seen 24 Sep 2026, 18:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 24, 2026 at 20:52 UTC
  • •The domain third-party.com is being exploited for ClickFix attacks targeting Windows users.
  • •Over 1,700 repositories reference this domain, increasing the risk of exposure.
  • •The attack method involves clipboard hijacking to execute malicious PowerShell commands.

The domain third-party.com, traditionally used as a documentation placeholder, is now serving a ClickFix attack targeting Windows users. This attack displays a fake Cloudflare verification page that tricks users into executing malicious PowerShell commands. The domain has been referenced in over 1,700 public repositories, making it a significant risk for developers. The ClickFix technique involves clipboard hijacking to facilitate the execution of hidden commands. Affected users are instructed to paste commands into the Windows Run dialog, which can lead to malware installation. The malicious activity was first reported by Manifold Security and confirmed by BleepingComputer. As of now, the domain has been marked as malicious on VirusTotal and Google Safe Browsing. The attack specifically targets Windows users, while macOS and Linux users see a harmless error message. Current status indicates that the attack chain is broken, as the payload URL is no longer resolving.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-01
ClickFix lure first observed
The domain third-party.com began serving malicious content targeting Windows users with a fake Cloudflare verification page.
The Hacker News
2026-09-24
Malicious activity reported
BleepingComputer confirmed the malicious use of third-party.com, detailing the attack method and its implications for Windows users.
BleepingComputer
2026-09-24
Domain marked malicious
The domain third-party.com has been flagged as unsafe on VirusTotal and Google Safe Browsing lists.
The Hacker News

More articles in this cluster (2)