P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Threats

Look-alike domain (typosquat): what it is and how it is attacked

A name registered to be mistaken for a real one at a glance.

Also known as

  • typosquat
  • cousin domain
  • homoglyph domain
  • impersonating domain
  • spoofed domain

Typing any of them into the editor finds this object.

Why it matters on a security diagram

It is the vehicle for most invoice fraud and a good deal of phishing, and it works because the reader is checking a name rather than comparing one. It costs the attacker a few pounds.

How it gets attacked, and what reduces it

How it gets attacked

  • Not applicable: it is the adversary's own infrastructure
  • Used to send mail that passes every sending check, because the attacker owns the domain and configures it correctly
  • Registered before it is used, sometimes months ahead

What reduces it

  • Monitor registrations close to your own names and your suppliers'
  • Treat a correct sending record as proof of nothing, since a name the attacker owns will always pass its own checks
  • Put the control on the action: verify a change of bank details through a number you already held

Where it sits

Group
Threats · The adversary and the things they bring.
Whose side, by default
Attacker · Working against the organisation.
Catalogue identifier
look-alike-domain

Reviewed . CC BY 4.0.

Others in threats

The threats group carries every object in it, including the ones with no page of their own.

Look-alike domain on your own diagram

Open the editor, press N, and type typosquat. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.

Open the diagram maker