Documentation placeholder domain used in ClickFix attacks

Summary

The domain third-party[.]com is being used to distribute malware, specifically a ClickFix lure that targets Windows machines and can alter PowerShell. This domain is often used in documentation as a placeholder, posing a risk to enterprises that might inadvertently direct users to the malicious site.

IFF Assessment

FOE

This article details a new method for distributing malware that exploits common developer practices, posing a direct threat to users and organizations.

Defender Context

Defenders should be aware of the malicious use of placeholder domains like third-party[.]com. Organizations should educate their employees about the risks of clicking on links in documentation, especially if they lead to unfamiliar domains, and ensure robust endpoint detection and response (EDR) solutions are in place to catch PowerShell-based attacks.

Read Full Story →