← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Phishing Via Typosquatting and Brand Impersonation: Trends and Tactics
From February to July 2024, an analysis of over 500 popular domains revealed more than 10,000 malicious lookalike domains employing typosquatting and brand impersonation techniques. Google, Microsoft, and Amazon were the most targeted brands, accounting for nearly 75% of phishing domains. Almost half of these domains used free Let's Encrypt TLS certificates to appear legitimate. The .com top-level domain was most prevalent, targeting English speakers. Internet Services, Professional Services, and Online Shopping were the most impersonated sectors. GoDaddy was the most abused domain registrar. Threat actors used these domains for malware distribution, credential theft, scams, and command-and-control communication.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| domain | acrobatbrowser.com | — | 2024-09-12 | |
| domain | adobevn.pro | — | 2024-09-12 | |
| domain | googleupdate.vip | — | 2024-09-12 | |
| domain | googqle.com | — | 2024-09-12 | |
| domain | offlice365.com | — | 2024-09-12 | |
| domain | onedrivesync.com | — | 2024-09-12 | |
| domain | play-store-google.com | — | 2024-09-12 | |
| domain | whatsapp-web.cn | — | 2024-09-12 | |
| domain | whatsapp2024.ru | — | 2024-09-12 | |
| hostname | html.phish.google | — | 2024-09-12 |