Placeholder domain used in dev docs now serves ClickFix attacks

· Original article ↗

Summary

The normally registered third-party.com domain is serving a fake Cloudflare verification page that uses a ClickFix technique to trick Windows users into running a PowerShell command. The command downloads and executes a script from elxxvvx[.]xyz. The payload domain no longer resolved during BleepingComputer's testing, and the archive previously distributed from it is unavailable.

Key points

  • The fake verification page copies a PowerShell command to the Windows Clipboard and instructs users to run it through the Windows Run dialog.
  • The command reconstructs a payload URL at elxxvvx[.]xyz/f, downloads a PowerShell script, and executes it.
  • A Hybrid Analysis report dated May 2, 2026, showed the script downloading a 134MB archive from https://elxxvvx[.]xyz/update2.zip, extracting it, and attempting to launch draw.io.exe.
  • The archive is no longer available, so BleepingComputer could not determine what the payload does.
  • Manifold Security reported the malicious use of third-party.com; BleepingComputer confirmed the fake verification page.
  • The domain is live, but the payload domain no longer resolved during testing. There have been no reports that the documented references led to successful ClickFix execution.

Tags

ClickFixSocial EngineeringMalicious DomainPowerShellMalware Delivery

Indicators of compromise

TypeIndicatorContext
DOMAINelxxvvx[.]xyzPayload domain used by the PowerShell command; it no longer resolved during BleepingComputer's testing.
DOMAINthird-party[.]comDomain serving the fake Cloudflare verification page used in the ClickFix attack.
URLhxxps[:]//elxxvvx[.]xyz/update2[.]zipURL from which the script was reported to download a 134MB archive.

MITRE ATT&CK

Products

Industries

Related Articles