Look-alike domain (typosquat): what it is and how it is attacked
A name registered to be mistaken for a real one at a glance.
Also known as
- typosquat
- cousin domain
- homoglyph domain
- impersonating domain
- spoofed domain
Typing any of them into the editor finds this object.
Why it matters on a security diagram
It is the vehicle for most invoice fraud and a good deal of phishing, and it works because the reader is checking a name rather than comparing one. It costs the attacker a few pounds.
How it gets attacked, and what reduces it
How it gets attacked
- Not applicable: it is the adversary's own infrastructure
- Used to send mail that passes every sending check, because the attacker owns the domain and configures it correctly
- Registered before it is used, sometimes months ahead
What reduces it
- Monitor registrations close to your own names and your suppliers'
- Treat a correct sending record as proof of nothing, since a name the attacker owns will always pass its own checks
- Put the control on the action: verify a change of bank details through a number you already held
Where it sits
- Group
- Threats · The adversary and the things they bring.
- Whose side, by default
- Attacker · Working against the organisation.
- Catalogue identifier
- look-alike-domain
Reviewed . CC BY 4.0.
Others in threats
- Extortion siteleak site · data leak site · DLS · shame site · negotiation portal · victim blogThe page an extortion group uses to name victims and publish what they took.
- Injected instructionprompt injection · indirect prompt injection · hostile prompt · poisoned content · instruction injectionText written to be read by an automated system rather than by a person, telling it to do something its owner did not ask for.
The threats group carries every object in it, including the ones with no page of their own.
Look-alike domain on your own diagram
Open the editor, press N, and type typosquat. The object is placed and connected to whatever was selected, and Tab adds the next one already joined to it. Nothing is uploaded: the page is served with a Content Security Policy that forbids the browser from making any outbound request at all.
Open the diagram maker