Criminals turn placeholder domain into ClickFix trap
Brief
A domain that has long appeared in software documentation, code examples, and developer test material is now being used to push a ClickFix attack against Windows users.
A placeholder domain stands in for a website in an example. The best-known is probably example. com . Another, third-party[. ]com , has often been used in documentation to represent an external website, API, or service.
However, there is a very important difference between the two: example. com is reserved for documentation, while third-party[. ]com is an ordinary domain. Anyone could register it, and someone did. Every document, test, and skill that hardcoded it now points readers and users to the attacker’s infrastructure.
Researchers at Manifold Security found that third-party[. ]com was serving a fake Cloudflare-style verification page to Windows visitors.
