ClickFix detection growth, H2 2025 to H1 2026: +108% (Source: ESET Threat Report, via InfoWorld)
A trusted placeholder becomes an attack vector
Web developers commonly write "third-party.com" into code samples and documentation as a generic stand-in for an outside website — the way "Jane Doe" stands in for a real name. That domain has now been registered by an unknown party and is serving a ClickFix malware lure to Windows machines, according to Manifold Security, which discovered the problem. The attack mimics a Cloudflare "are you human?" verification screen, poisons the user's clipboard, and instructs them to press Win+R and paste — a command that then pulls and runs a remote PowerShell payload without triggering existing protections.
The risk is structural, not incidental. A more familiar placeholder, example.com, is reserved by IANA (the Internet Assigned Numbers Authority) specifically so it can never be registered or resolve to a live site. third-party.com carries no such protection — anyone can register it, and someone did. Organizations that have copied the domain into internal wikis, training materials, sample configurations, or customer-facing documentation may now be inadvertently pointing employees or customers toward a live malware delivery site.
Part of a technique that is accelerating
ClickFix is not a new technique — attackers have used variations of it for roughly two years with different lures. But detection volume is climbing sharply, according to ESET's Threat Report cited by InfoWorld.
Following Manifold Security's disclosure, the third-party.com domain has been reported to its registrar, Network Solutions. Registrar action can take the specific domain offline, but it does not undo any copies of the address already embedded in an organization's own documentation, code repositories, or support scripts — nor does it address the next placeholder domain an attacker chooses to register.
What a budget-holder should ask
This incident is a reminder that documentation conventions carry operational risk once they leave the page. Ask your security and engineering leads: does any internal documentation, code repository, or customer-facing content reference third-party.com or other unregistered placeholder strings that could resolve to a live site? Is there a policy requiring only IANA-reserved placeholders (example.com, example.org, example.net) in code and training material? Are Win+R clipboard-paste execution patterns monitored or restricted by endpoint policy? And is DNS or proxy filtering in place to block newly registered or reputationally unverified domains before they reach end users?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: InfoWorld.





