Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-611 — BitSquatting
CAPEC-611

BitSquatting

TLP:CLEAR

Description

Typical severity: Medium. Likelihood of attack: Low. An adversary registers a domain name one bit different than a trusted domain. A BitSquatting attack leverages random errors in memory to direct Internet traffic to adversary-controlled destinations. BitSquatting requires no exploitation or complicated reverse engineering, and is operating system and architecture agnostic. Experimental observations show that BitSquatting popular websites could redirect non-trivial amounts of Internet traffic to a malicious entity.

Mitigation

Authenticate all servers and perform redundant checks when using DNS hostnames. | When possible, use error-correcting (ECC) memory in local devices as non-ECC memory is significantly more vulnerable to faults.

Details

Platforms
Social-engineering
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.