Act
active
Placeholder domain 'third-party.com' now serves ClickFix malware
- Engineer — Plan: Audit your developer documentation, internal wikis, and code examples for placeholder domains that resolve to live addresses — ’third-party.com’ is now actively malicious. This quarter, establish a doc review process to catch example domains before they reach users.
- SOC/IR — Act: Search proxy and DNS logs for connections to third-party.com; hunt for ClickFix-pattern PowerShell execution following fake Cloudflare CAPTCHA pages, particularly on developer workstations where traffic to doc-linked domains is expected and may slip past scrutiny.
- Leader — Learn: A subtle supply-chain-adjacent technique where expired or unclaimed placeholder domains in developer documentation become lure infrastructure — no immediate leadership action required, but useful context for developer-endpoint risk discussions.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.