BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Placeholder domain third-party.com now serves ClickFix malware

Long-trusted placeholder domain hijacked to deliver ClickFix malware to Windows users.

  • The long-trusted documentation placeholder domain “third-party[.]com” has been weaponized to serve a ClickFix malware lure to Windows users.
  • Unlike “example[.]com,” the domain was not IANA-reserved and was registered by an attacker to serve malicious payloads from a previously trusted source.
  • Manifold Security identified 13 additional non-reserved placeholder domains, including “yoursite[.]com” and “your-domain[.]com,” which are serving scams and scareware.

The “third-party[.]com” domain, a widely used placeholder in software documentation for years, has been hijacked to deploy a ClickFix social engineering attack targeting Windows browsers while showing harmless decoys to others. According to Manifold Security, researchers discovered that the domain, which is not IANA-reserved, was registered by an unknown actor who now serves malicious content from the trusted address.

- Advertisement -

“This is now a live pointer to a ClickFix server,” said Ax Sharma, Head of Research at Manifold Security. The attack relies on clipboard hijacking to inject malicious commands, tricking users into pasting and executing the code via the Windows Run dialog. The domain has been flagged as malicious on VirusTotal and Google’s Safe Browsing list.

Meanwhile, macOS users visiting the page are shown a fake security prompt that simply states, “macOS is not supported.” The danger is amplified by the domain’s presence in over 1,700 public GitHub repositories, including AI agent skills and documentation that cite it as a valid example endpoint.

A file scan cannot detect the threat, as the malicious payload only appears when a Windows user’s agent requests the page. Manifold Security has since identified 13 more vulnerable placeholder domains like “your-domain[.]com” and “yoursite[.]com,” which are serving scareware and investment scams to macOS users.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

- Advertisement -

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Microsoft Stock Hits $500, Analyst Sees Rally to $575

Microsoft stock (NASDAQ: MSFT) opened at $500 on Thursday, a key resistance level it...

Solana hires Binance CMO, Polygon exec to lead strategy, payments

Rachel Conlan joins the Solana Foundation as chief strategy officer after three years as...

Kalshi AI Ad Steals YouTuber’s Video, Turns Him White

Kalshi is accused of using an AI-generated ad that stole a YouTube video from...

HIFI raises $37M Series A for stablecoin infrastructure

Stablecoin infrastructure provider HIFI raises $37 million in a Series A led by Left...

Critical WordPress RCE bug actively exploited within hours

Threat actors are actively exploiting a critical WordPress vulnerability, CVE-2026-87902, just hours after its...

Must Read

6 Best VPN Providers That Accept Monero

Privacy and anonymity are probably the most important things that we should all consider in today's internet era. Although there are a lot of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading