Third-party.com fake Cloudflare verification ClickFix campaign targeting Windows users
Campaign
Summary
Hide ▲
Show ▼
The third-party.com domain is hosting a ClickFix lure that impersonates a Cloudflare security check and pushes Windows users to run malicious PowerShell commands. The page uses clipboard poisoning and a fake verification flow to steer victims toward a payload chain on elxxvvx[.]xyz. The abuse turns a long-used placeholder hostname into an active delivery point for malware installation attempts.
Related Happenings
ClickFix-based TELEPUZ distribution campaign
Campaign
H score35
First: 16.07.2026 15:50
Last: 16.07.2026 15:50
Sources 1
About this happening:
The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
ClickFix-based TELEPUZ distribution campaign
CampaignAbout this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
ClickFix mitigation guidance for Windows and macOS
Defensive Guidance
H score34
First: 30.06.2026 15:00
Last: 30.06.2026 15:00
Sources 1
About this happening:
Organizations are being urged to harden defenses against ClickFix on Windows and macOS, reducing the chance that social-engineering lures can turn trusted dialogs into...
ClickFix mitigation guidance for Windows and macOS
Defensive GuidanceAbout this happening: Organizations are being urged to harden defenses against ClickFix on Windows and macOS, reducing the chance that social-engineering lures can turn trusted dialogs into...
Openew[.]app cloaked malware download portal
Malware Activity
H score26
First: 29.05.2026 21:21
Last: 29.05.2026 21:21
Sources 1
About this happening:
The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...
Openew[.]app cloaked malware download portal
Malware ActivityAbout this happening: The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...
OAuth device-code phishing campaign targeting SaaS accounts
Campaign
H score43
First: 04.04.2026 17:17
Last: 04.04.2026 17:17
Sources 1
About this happening:
A device code phishing campaign now includes NovaCookies, a $320/month adversary-in-the-middle kit that proxies Microsoft 365 sign-ins and steals authenticated ses...
OAuth device-code phishing campaign targeting SaaS accounts
CampaignAbout this happening: A device code phishing campaign now includes NovaCookies, a $320/month adversary-in-the-middle kit that proxies Microsoft 365 sign-ins and steals authenticated ses...
Timeline
-
24.09.2026 01:46 2 articles · 2h ago
Manifold Security reports a fake Cloudflare verification ClickFix lure on third-party.com
Initial DisclosureManifold Security first reports malicious use of third-party.com after finding it in public AI skills and MCP server documentation, and BleepingComputer confirms the page shows a fake Cloudflare "Performing security verification" CAPTCHA that copies malicious PowerShell commands for Windows users.
Show sources
- Placeholder domain used in dev docs now serves ClickFix attacks — www.bleepingcomputer.com — 24.09.2026 01:46
- Placeholder domain used in dev docs now serves ClickFix attacks — www.bleepingcomputer.com — 24.09.2026 01:46
-
02.05.2026 03:00 1 articles · 4mo ago
PowerShell script from third-party.com downloads update2.zip payload
Technical Analysis UpdateA Hybrid Analysis report dated May 2, 2026 shows third-party.com distributing a PowerShell script that downloads a 134MB archive from https://elxxvvx[.]xyz/update2.zip, saves it as update26.zip, extracts it, and attempts to launch draw.io.exe.
Show sources
- Placeholder domain used in dev docs now serves ClickFix attacks — www.bleepingcomputer.com — 24.09.2026 01:46