Skip to content
DnsLister Forum

Where domain hunters compare notes

Placeholder domain used in dev docs now serves ClickFix attacks

The "third-party.com" domain, a ubiquitous placeholder in developer documentation and code examples, has been weaponized. It now serves a fake Cloudflare verification page that attempts to trick Windows users into running malicious PowerShell commands—a classic ClickFix attack chain.

Technical Breakdown – Attack Vector: Users visiting sites or following code examples referencing third-party.com are redirected to a fake Cloudflare DDoS protection page. – Payload Delivery: The page instructs users to press Windows Key + R, paste a PowerShell command, and execute it. This is a social engineering technique to bypass browser security controls. – Malware: The PowerShell command downloads and executes an information stealer (likely Vidar or similar), targeting credentials, browser data, and cryptocurrency wallets. – IOCs: The domain third-party.com itself is the initial pivot. Monitor for outbound connections to it or associated IPs. No specific hashes provided in the report.

Defense Block third-party.com at the DNS/proxy level if not required for legitimate development workflows. Educate users that legitimate Cloudflare verification never requires manual PowerShell execution. Enable PowerShell logging and monitor for suspicious Invoke-Expression or IEX commands.

Source: https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks/

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *