Skip to main content

third-party.com Placeholder Domain Now Serves ClickFix

0
Medium
Published: 09/24/2026 (09/24/2026, 17:09:58 UTC)
Source: AlienVault OTX General

Description

The domain third-party[.]com, historically used as a documentation placeholder similar to example.com, has been compromised and now serves ClickFix lures to Windows users while displaying harmless content to other operating systems. Since at least June 2026, Windows visitors receive a fake Cloudflare verification page that poisons the clipboard with a malicious PowerShell command, instructing users to press Win+R and paste the payload. The domain appears in over 1,500 files across 1,700+ repositories from trusted sources including Chromium, Sanity, and Vercel. Unlike example.com, third-party[.]com is not IANA-reserved, allowing adversaries to register and weaponize it. The attack leverages social engineering to bypass security tools by using signed Windows binaries, making detection difficult through traditional scanning methods.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 20:17:52 UTC

Technical Analysis

The third-party.com domain, used as a documentation placeholder similar to example.com, has been compromised and weaponized to deliver ClickFix malware lures to Windows users. Visitors on Windows are presented with a fake Cloudflare verification page that poisons their clipboard with a malicious PowerShell command, instructing them to execute it via the Run dialog (Win+R). This social engineering tactic leverages signed Windows binaries to bypass security detections. The domain is referenced in over 1,500 files across more than 1,700 repositories from trusted sources such as Chromium, Sanity, and Vercel, increasing the attack surface. Because third-party.com is not IANA-reserved, adversaries were able to register and exploit it. The campaign has been active since at least June 2026 and targets Windows users specifically, while showing benign content to other operating systems.

Potential Impact

Windows users visiting third-party.com are at risk of executing a malicious PowerShell payload due to clipboard poisoning and social engineering. The widespread use of the domain in trusted repositories increases the likelihood of exposure. The attack bypasses traditional security tools by using signed Windows binaries, making detection and prevention more challenging. There is no indication of active exploitation in the wild beyond this campaign, and no direct CVE or software vulnerability is involved.

Defensive Guidance

No official patch or fix is available as this is a social engineering campaign leveraging a compromised domain rather than a software vulnerability. Defenders should educate users to avoid executing clipboard-pasted commands from untrusted sources, especially when prompted by unexpected verification pages. Security teams should monitor for suspicious clipboard activity and PowerShell execution triggered by user input. Since the domain is not IANA-reserved, organizations should avoid using third-party.com as a placeholder domain in documentation or code to prevent accidental exposure. Traditional signature-based detection may be ineffective due to the use of signed binaries; behavioral detection and user awareness are critical.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.manifold.security/blog/third-party-com-placeholder-clickfix"]
Pulse Id
6ab559662b978ca478cf0b21

Indicators of Compromise

Domain

ValueDescriptionCopy
domainelxxvvx.xyz
—

Url

ValueDescriptionCopy
urlhttp://elxxvvx.xyz/f
—
urlhttp://elxxvvx.xyz/f'
—
urlhttp://third-party.com/token
—
urlhttp://third-party.com/widget.js
—

Threat ID: 6ab581e9f7a7c54106c7b233

Added to database: 09/24/2026, 20:02:49 UTC

Last enriched: 09/24/2026, 20:17:52 UTC

Last updated: 09/25/2026, 01:47:34 UTC

Views: 15

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses