Documentation placeholder domain used in ClickFix attacks
Summary
The domain third-party[.]com is being used to distribute malware, specifically a ClickFix lure that targets Windows machines and can alter PowerShell. This domain is often used in documentation as a placeholder, posing a risk to enterprises that might inadvertently direct users to the malicious site.
IFF Assessment
This article details a new method for distributing malware that exploits common developer practices, posing a direct threat to users and organizations.
Defender Context
Defenders should be aware of the malicious use of placeholder domains like third-party[.]com. Organizations should educate their employees about the risks of clicking on links in documentation, especially if they lead to unfamiliar domains, and ensure robust endpoint detection and response (EDR) solutions are in place to catch PowerShell-based attacks.