CuraSec

Act active

Placeholder domain 'third-party.com' now serves ClickFix malware

2026-09-24 15:49 UTC · BleepingComputer · read the source ↗ #clickfix#social-engineering#supply-chain
  • Engineer — Plan: Audit your developer documentation, internal wikis, and code examples for placeholder domains that resolve to live addresses — ’third-party.com’ is now actively malicious. This quarter, establish a doc review process to catch example domains before they reach users.
  • SOC/IR — Act: Search proxy and DNS logs for connections to third-party.com; hunt for ClickFix-pattern PowerShell execution following fake Cloudflare CAPTCHA pages, particularly on developer workstations where traffic to doc-linked domains is expected and may slip past scrutiny.
  • Leader — Learn: A subtle supply-chain-adjacent technique where expired or unclaimed placeholder domains in developer documentation become lure infrastructure — no immediate leadership action required, but useful context for developer-endpoint risk discussions.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.