🎯 Goal

Today I explored typosquatting, a technique attackers use to trick users into visiting malicious domains that closely resemble legitimate websites.

The objective was to understand:

  • how attackers register deceptive domains
  • how these domains are used in attacks
  • how defenders detect them.

🛠 What I Did

I studied how attackers exploit common typing mistakes when entering URLs.

For example, instead of:

google.com

An attacker may register:

g00gle.com
gooogle.com
goog1e.com

These domains visually resemble the legitimate site but are controlled by attackers.


🔗 Key Cybersecurity Connections

Typosquatting domains are frequently used for:

  • phishing pages
  • credential harvesting
  • malware downloads
  • advertising fraud

A typical attack flow might look like:

User mistypes domain
↓
Browser loads malicious website
↓
Fake login page displayed
↓
Credentials stolen


🔍 Investigation Questions

If suspicious domain activity appeared in logs or alerts, a SOC analyst might investigate:

  • What domain was accessed by the user or endpoint?
  • Does the domain resemble a well-known legitimate domain?
  • When was the suspicious domain registered?
  • Are other users inside the organization accessing the same domain?
  • Does the domain resolve to infrastructure associated with known malicious campaigns?
  • Did any credentials or sensitive information get submitted to the site?

These questions help determine whether the domain is part of a phishing or impersonation campaign.


🚨 Detection Opportunities

Possible detection strategies for typosquatting attacks include:

  • monitoring access to newly registered domains
  • detecting domain names visually similar to trusted brands
  • correlating DNS queries with threat intelligence feeds
  • alerting when internal users access suspicious look-alike domains
  • monitoring login events following visits to suspicious websites

Security telemetry useful for these detections includes:

  • DNS logs
  • proxy logs
  • email gateway alerts
  • endpoint browser telemetry.

🧭 MITRE ATT&CK Techniques

Typosquatting activity is commonly associated with the following MITRE ATT&CK techniques:

  • T1566 – Phishing
  • T1583 – Acquire Infrastructure
  • T1584 – Compromise Infrastructure
  • T1608 – Stage Capabilities

These techniques illustrate how attackers prepare and deliver phishing infrastructure designed to deceive users.


⚠ Challenges

The difficulty in defending against typosquatting is that the domains can look extremely convincing.

Attackers also combine typosquatting with:

  • phishing emails
  • fake login portals
  • cloned websites.

📚 What I Learned

Defenders often detect typosquatting using:

  • domain similarity monitoring
  • threat intelligence feeds
  • brand protection tools
  • DNS monitoring

Companies sometimes proactively register common typos of their own domains to prevent abuse.


➡ Next Steps

Next areas of interest include:

  • malicious infrastructure used by attackers
  • frameworks used during penetration testing and real attacks

🧠 Reflection

Typosquatting demonstrates how attackers exploit human behavior rather than technical vulnerabilities.

Even a small mistake when typing a URL can lead to credential compromise.


🧩 Lessons Learned

What worked

Studying real examples made the concept easy to visualize.

What broke

At first it seemed too simple to be effective.

Why it broke

In reality, attackers rely on scale and automation.

Fix / takeaway

Even small weaknesses in user behavior can become large attack surfaces.


📈 Skill Progression Context

Understanding domain-based attacks is important for:

  • phishing investigations
  • threat intelligence
  • SOC monitoring of suspicious domains

This builds on earlier learning about email-based attacks.