Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns CAPEC-630 — TypoSquatting
CAPEC-630

TypoSquatting

TLP:CLEAR

Description

Typical severity: Medium. Likelihood of attack: Low. An adversary registers a domain name with at least one character different than a trusted domain. A TypoSquatting attack takes advantage of instances where a user mistypes a URL (e.g. www.goggle.com) or not does visually verify a URL before clicking on it (e.g. phishing attack). As a result, the user is directed to an adversary-controlled destination. TypoSquatting does not require an attack against the trusted domain or complicated reverse engineering.

Mitigation

Authenticate all servers and perform redundant checks when using DNS hostnames. | Purchase potential TypoSquatted domains and forward to legitimate domain.

Details

Platforms
Social-engineering
Added
Jul 14, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.