• Overview
    • Scam Map
    • Kill Chain
Recents

    Conversations will appear here

Technique

Lookalike Domain

Also known as: Typosquatting, Domain Spoofing, Homograph Attack, IDN Homograph Attack, URL Spoofing, Doppelganger Domain

DELIVERY

Registering domains that visually mimic legitimate websites through typos, character substitution, or homoglyphs to deceive victims into visiting malicious sites.

Common attack flows

How it fits in a scam

This technique shows up duringDELIVERY

Before

This is often where the scam begins.

After

  • Credential TheftCOMPROMISE
  • Payment Card TheftCOMPROMISE

Defense

How to defend against this

How to spot it

  • Carefully inspect URLs character-by-character before clicking or entering data
  • Look for subtle misspellings like micorsoft.com or arnazon.com
  • Check for unusual TLDs like .bond .xyz .top on supposedly official sites
  • Government sites use .gov - anything else is fake
  • Watch for mixed character sets where Cyrillic a looks like Latin a
  • Hover over links to reveal actual destination URL
  • Browser warnings about deceptive sites

Tools you can use

  • DNS FilteringCost low · Effect high
  • Browser Security ExtensionCost low · Effect medium
  • Mobile Security AppCost low · Effect high

Steps you can take

  • Verify HTTPS ConnectionsCost low · Effect medium
  • Direct Source VerificationCost low · Effect high

Further reading

  • Wikipedia

    Typosquatting overview

  • Wikipedia

    Homograph attack explanation

  • Huntress

    Typosquatting explained

  • CEUR Workshop

    TypoAlert browser extension research

Related techniques

Same stage

  • Phishing Email
  • Smishing
  • Vishing
  • Deepfake Voice Call
  • SEO Poisoning
  • +16 more

Similar defense

  • Clipboard Hijacking
  • Malicious App Installation
  • Overlay Attack
  • Man In The Middle
  • Ad Network Tracking
  • +11 more