Malware

Typosquatting

Typosquatting is registering a name one slip away from a real one, such as a domain, package, or account, and waiting for people to mistype it.

How it is measured

List the variants of your name: missing letter, swapped letters, doubled letter, wrong TLD, hyphenation, and lookalike characters. Check which are registered and by whom with WHOIS or RDAP, and what they serve: a parked page, a login clone, or a redirect. Package registries have the same trick, so search npm and PyPI for names near yours.

Measure exposure by registration date, whether the name has mail records, whether it has a certificate, and whether it serves your logo or copy. Certificate transparency logs show newly issued certificates on lookalike names.

Worked example

A credit union at 'northpeak.example' finds 'northpeek.example' registered 9 days ago with a Let's Encrypt certificate and MX records. It serves a clone of the login page. Support tickets show two members who typed the wrong address from a printed flyer.

The credit union files a takedown with the registrar and adds the domain to its internal blocklist and mail filter, because the MX records mean the name can also send mail that looks internal.

How it differs

Brand squatting registers a name that includes your brand, like northpeak-support.example, and is deliberate about the words, not the typos. Typosquatting relies on a keyboard slip or a misread. The first catches people who search for you; the second catches people who know your address and mistype it.

Common errors

Registering only the .com. Ignoring package names when you publish libraries. Assuming a padlock on the wrong domain makes it safe. Skipping mail records, which attackers use to impersonate you. Not monitoring new registrations.

In practice

Register the obvious misspellings and the TLDs that matter, set up monitoring for new lookalike registrations, and publish DMARC with p=reject so your exact domain cannot be spoofed. For packages, reserve the plausible names and tell users the exact install command.

See also

Brand squat, Supply-chain attack

Sources

Count this on a real site.

Watch my website