Placeholder domain abused to deliver ClickFix malware
🛡️ third-party[.]com is being used to deliver a ClickFix lure that targets Windows systems and sidesteps protections, Manifold Security reports. The site impersonates a Cloudflare “are you human?” check, poisons the clipboard and instructs users to paste a command that runs a remote PowerShell payload. Unlike reserved placeholders such as example.com, third-party[.]com was available for registration and was abused to trap unwary developers and enterprise users.
