PULSE NAME
Phishing Via Typosquatting and Brand Impersonation: Trends and Tactics
WHITE AlienVault 2024-09-12 Modified: 2024-09-12
10
IOCs
LOW VOLUME
From February to July 2024, an analysis of over 500 popular domains revealed more than 10,000 malicious lookalike domains employing typosquatting and brand impersonation techniques. Google, Microsoft, and Amazon were the most targeted brands, accounting for nearly 75% of phishing domains. Almost half of these domains used free Let's Encrypt TLS certificates to appear legitimate. The .com top-level domain was most prevalent, targeting English speakers. Internet Services, Professional Services, and Online Shopping were the most impersonated sectors. GoDaddy was the most abused domain registrar. Threat actors used these domains for malware distribution, credential theft, scams, and command-and-control communication.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Atera Remote Access Trojan TacticalRMM
Indicators of Compromise (10)
All domain hostname
TYPEINDICATORDESCRIPTIONCREATED
domain acrobatbrowser.com 2024-09-12
domain adobevn.pro 2024-09-12
domain googleupdate.vip 2024-09-12
domain googqle.com 2024-09-12
domain offlice365.com 2024-09-12
domain onedrivesync.com 2024-09-12
domain play-store-google.com 2024-09-12
domain whatsapp-web.cn 2024-09-12
domain whatsapp2024.ru 2024-09-12
hostname html.phish.google 2024-09-12