Find notable cyber news and cases, enriched with sources, timelines, and signals.

Third-party.com fake Cloudflare verification ClickFix campaign targeting Windows users

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

The third-party.com domain is hosting a ClickFix lure that impersonates a Cloudflare security check and pushes Windows users to run malicious PowerShell commands. The page uses clipboard poisoning and a fake verification flow to steer victims toward a payload chain on elxxvvx[.]xyz. The abuse turns a long-used placeholder hostname into an active delivery point for malware installation attempts.

Related Happenings

ClickFix-based TELEPUZ distribution campaign

Campaign
H score35 First: 16.07.2026 15:50 Last: 16.07.2026 15:50 Sources 1

About this happening: The ClickFix-based TELEPUZ distribution campaign is pushing TELEPUZ through websites infected with lures, increasing the chance that victims run malicious commands and...

LastPass and Bitwarden users targeted by fake-security-notice phishing campaign

Campaign
H score31 First: 14.07.2026 18:31 Last: 14.07.2026 18:31 Sources 1

About this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...

ClickFix mitigation guidance for Windows and macOS

Defensive Guidance
H score34 First: 30.06.2026 15:00 Last: 30.06.2026 15:00 Sources 1

About this happening: Organizations are being urged to harden defenses against ClickFix on Windows and macOS, reducing the chance that social-engineering lures can turn trusted dialogs into...

Openew[.]app cloaked malware download portal

Malware Activity
H score26 First: 29.05.2026 21:21 Last: 29.05.2026 21:21 Sources 1

About this happening: The openew[.]app malware-delivery activity now also uses legitimate ChatGPT shared pages as the first lure, with Google ads and SEO poisoning sending victims to a...

OAuth device-code phishing campaign targeting SaaS accounts

Campaign
H score43 First: 04.04.2026 17:17 Last: 04.04.2026 17:17 Sources 1

About this happening: A device code phishing campaign now includes NovaCookies, a $320/month adversary-in-the-middle kit that proxies Microsoft 365 sign-ins and steals authenticated ses...

Timeline

  1. 24.09.2026 01:46 2 articles · 2h ago

    Manifold Security reports a fake Cloudflare verification ClickFix lure on third-party.com

    Initial Disclosure

    Manifold Security first reports malicious use of third-party.com after finding it in public AI skills and MCP server documentation, and BleepingComputer confirms the page shows a fake Cloudflare "Performing security verification" CAPTCHA that copies malicious PowerShell commands for Windows users.

    Show sources
  2. 02.05.2026 03:00 1 articles · 4mo ago

    PowerShell script from third-party.com downloads update2.zip payload

    Technical Analysis Update

    A Hybrid Analysis report dated May 2, 2026 shows third-party.com distributing a PowerShell script that downloads a 134MB archive from https://elxxvvx[.]xyz/update2.zip, saves it as update26.zip, extracts it, and attempts to launch draw.io.exe.

    Show sources