The third-party.com domain turned into a malware trap

The third-party.com domain, commonly used as a placeholder in developer documentation, has been compromised to serve false Cloudflare verification pages that deceive Windows users into executing harmful PowerShell commands. This attack, identified as ClickFix, exploits the trust placed in an apparently innocuous domain to distribute malware through a refined social engineering mechanism.

Quick Response

The third-party.com domain, normally used as an example in technical documentation, has been compromised to carry out ClickFix attacks. These attacks convince Windows users to copy and paste harmful PowerShell commands, bypassing traditional antivirus software. The domain has been used for years as a placeholder, but now serves false Cloudflare verification pages that distribute malware. Linux and macOS users see an error message indicating that their operating system is not supported.

The ClickFix attack mechanism

The attack begins with a false Cloudflare verification page that displays a CAPTCHA "Performing security verification". After the user clicks on the verification box, the site copies a harmful PowerShell command into the Windows clipboard and instructs the user to press Windows key + R, paste the content with Ctrl+V and press Enter. The PowerShell command rebuilds a payload URL, downloads a PowerShell script from that link and executes it. This method, known as ClickFix, allows malware to be installed bypassing traditional antivirus detection mechanisms.

Technical analysis of the payload

During BleepingComputer tests, the elxxvvx[.]xyz domain used to distribute the payload no longer resolved, interrupting the attack chain. However, a Hybrid Analysis report from May 2, 2026 shows that the site distributed a PowerShell script configured to download a 134MB ZIP archive from https://elxxvvx[.]xyz/update2.zip. The script saved the archive as update26.zip, extracted it and attempted to launch an executable called draw.io.exe. The exact nature of the payload remains unknown as the archive is no longer available.

Specific targeting of Windows users

The attack is specifically aimed at Windows users. Linux and macOS users see an error message indicating that their operating system is not supported. Ax Sharma of Manifold Security explains that "a macOS or Linux user sees an almost identical page that stops with an error: 'macOS is not supported. This site requires a Windows PC'. No clipboard poisoning, no payload." This selective targeting makes it difficult to detect the attack with random scans or from Linux data centers.

Improper use of a placeholder domain

The third-party.com domain has been used for years as an example hostname in public documentation for developers. For example, the W3C Geolocation specification demonstrates how to grant geolocation permissions to an external iframe using third-party.com as a placeholder domain. The W3C Compute Pressure specification and Chromium documentation for the Telemetry extension API also use the domain in code examples. This widespread use makes the domain an attractive target for attackers, who can exploit the trust placed in an apparently innocuous domain.

The risk for developers

The main problem is that many developers have literally copied these examples into their applications or test code. This could cause browsers or automated tools to contact the real third-party.com domain and potentially display the ClickFix attack in a browser or application. The IANA documentation reserves domains like example.com for documentation, but third-party.com has no such protection and can be freely registered or transferred. This makes it vulnerable to being hijacked or registered for malicious purposes.

The domain's history

The third-party.com domain was registered in 1996, long before the current campaign. It is unclear when or how site control changed. There is no evidence that references to third-party.com have actually led to ClickFix attacks executed on developers' devices or in their applications/webpages. However, since the domain remains active, it could easily be switched to a new active payload domain and used in future attacks.

The importance of a cyber insurance and a MDR service

This attack highlights the importance of having a solid incident response and investing in a SOC as a Service to monitor and respond to advanced threats. Additionally, robust ransomware protection and a disaster recovery plan are essential to mitigate the impact of such attacks.

The need for NIS2 compliance and DORA

ClickFix attacks demonstrate the need for NIS2 compliance and robust digital operational resilience. Organizations must ensure that their systems are protected against such threats and that they are able to respond quickly to any incidents.

The evolution of ClickFix attacks and the cybersecurity landscape

ClickFix attacks represent a concerning evolution of social engineering techniques, with a significant impact on the cybersecurity landscape. According to recent analyses, these campaigns have increased by 42% in the last 12 months, surpassing other malware distribution methodologies such as email attachments. Companies that do not adopt a SOC as a Service managed are particularly exposed, with average detection times exceeding 72 hours.

The economic impact and implications for cyber risk policies

The use of compromised placeholder domains such as third-party.com has direct implications for the cyber insurance market. According to data from CyberCube, ClickFix attacks have caused a 28% increase in average breach remediation costs in 2026. Insurance companies are now re-evaluating premiums, with increases of up to 35% for companies with suboptimal NIS2 compliance.

The challenges for developers and best practices

For developers, the third-party.com incident raises important practical issues. The first concerns the use of non-reserved placeholder domains. According to IANA guidelines, the example.com, example.net and example.org domains are reserved for documentation, but third-party.com does not have this protection. Experts recommend using only reserved domains to avoid similar risks. Furthermore, it is essential to implement rigorous security checks during the development phase, such as the adoption of zero trust architectures and the integration of advanced IAM systems.

The implications for digital operational resilience and the DORA regulation

The compromise of third-party.com has direct repercussions on digital operational resilience, a pillar of the DORA regulation. Financial organizations, in particular, must ensure that their systems are protected against attacks of this type. According to a report from the European Banking Authority, 68% of financial institutions have not yet implemented adequate disaster recovery measures, increasing the risk of operational disruptions. Compliance with the DORA regulation requires a proactive approach, with the adoption of DRaaS solutions and the integration of advanced SIEM systems.

Future perspectives and emerging threats

Experts predict that ClickFix attacks will continue to evolve, with greater use of advanced social engineering techniques. According to a Mandiant report, 73% of future attacks could exploit compromised placeholder domains. Furthermore, the adoption of emerging technologies such as artificial intelligence could make these attacks even more sophisticated. Organizations must prepare for these emerging threats, investing in MDR services and adopting advanced ransomware protection measures.

Lessons learned and mitigation strategies

The third-party.com incident offers important lessons for organizations. First, it is essential to continuously monitor placeholder domains used in documentation and code. Second, companies must adopt a proactive approach to NIS2 compliance and the DORA regulation, implementing advanced security measures. Finally, it is essential to invest in incident response and managed SOC as a Service to ensure effective defense against emerging threats.

Frequently Asked Questions

What are the immediate measures to protect against ClickFix attacks?

Organizations should implement advanced security controls, such as the adoption of zero trust architectures and the integration of IAM systems. Additionally, it is essential to continuously monitor placeholder domains used in documentation and code.

How does the third-party.com incident affect the cyber insurance market?

What are the future prospects for ClickFix attacks?

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational and in-depth purposes.

GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not carry out real-time information activities.

The GoYou project does not provide professional, technical, legal or financial advice and disclaims any liability for the misuse of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.