Criminals turn placeholder domain into ClickFix trap
Executive Summary
A domain commonly used as a placeholder in software examples—third-party.com—has been hijacked by criminals to host a fake verification page. The page instructs Windows users to run a PowerShell command, effectively turning the domain into a ClickFix trap. The malicious activity was identified by Malwarebytes Labs.
Intelligence Metadata - Source Publisher: Malwarebytes Labs - Published Date: 2026-09-25T12:42:11+00:00 - Category: threat-intel
Original Description: A domain used in software examples—third-party[.]com—now serves up a fake verification page that tells Windows users to run a PowerShell command.
"Edison failed 10,000 times before he made the electric light. Do not be discouraged if you fail a few times."
— Napoleon Hill
Source: Malwarebytes Labs