home.social

#typosquat — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #typosquat, aggregated by home.social.

fetched live
  1. #typosquat attack now also in the #golang eco system

    "... due to Go’s caching mechanism, developers installing the package using the go CLI continued to download the cached malicious version from the Go Module Mirror, rather than the updated, benign version."

    socket.dev/blog/malicious-pack

    #devsecops #security #cloud

  2. #typosquat attack now also in the #golang eco system

    "... due to Go’s caching mechanism, developers installing the package using the go CLI continued to download the cached malicious version from the Go Module Mirror, rather than the updated, benign version."

    socket.dev/blog/malicious-pack

    #devsecops #security #cloud

  3. #typosquat attack now also in the #golang eco system

    "... due to Go’s caching mechanism, developers installing the package using the go CLI continued to download the cached malicious version from the Go Module Mirror, rather than the updated, benign version."

    socket.dev/blog/malicious-pack

    #devsecops #security #cloud

  4. #typosquat attack now also in the #golang eco system

    "... due to Go’s caching mechanism, developers installing the package using the go CLI continued to download the cached malicious version from the Go Module Mirror, rather than the updated, benign version."

    socket.dev/blog/malicious-pack

    #devsecops #security #cloud

  5. Threat actor using lookalike domains that drive through a traffic distribution system (TDS) to illegal gambling and malicious content. This actor runs a TDS using a few different domains, including choto[.]xyz and choto[.]click. The attack chain typically begins when an internet user unknowingly mistypes a website (e.g. dizscord[.]com instead of discord.com). Subsequently, the user is profiled via one or two TDS servers and then conditionally redirected to a fraudulent webpage. Earlier this year, they ran campaigns that leveraged a second stage TDS (victory-leads[.]xyz) that conditionally routed users to different malicious content based on their geo-location (see attached image). We recommend blocking the following TDS domains; doing so will effectively disrupt the attack chains that are conducted by this actor. Currently, only choto[.]click appears to be actively used. We have been tracking this TDS since Spring 2023.

    <Lookalike Domains>
    donga[.]delivery (imitating donga.com - South Korean newspaper company)
    tutorialspoint[.]pics (imitating tutorialspoint.com - video tutorial education service)
    icicibank[.]observer (imitating icicibank.com - Indian banking)
    netflixg[.]com (imitating netflix.com - video streaming service)
    capktalone[.]com (imitating capitalone.com - American banking company)
    cbssportas[.]com (imitating cbssports.com - American sports network)
    betwah[.]de (imitating betway.com - British gambling company)

    <TDS Domains>
    choto[.]click
    choto[.]xyz
    choto[.]store
    victory-leads[.]xyz

    <Fraud Landing Page Domains>
    lotto60[.]com
    joya[.]casino
    tickets[.]love

    #dns #cybersecurity #InfobloxThreatIntel #Infoblox #tds #gambling #scam #lookalike #typosquat #threatintel #cybercrime

  6. Threat actor using lookalike domains that drive through a traffic distribution system (TDS) to illegal gambling and malicious content. This actor runs a TDS using a few different domains, including choto[.]xyz and choto[.]click. The attack chain typically begins when an internet user unknowingly mistypes a website (e.g. dizscord[.]com instead of discord.com). Subsequently, the user is profiled via one or two TDS servers and then conditionally redirected to a fraudulent webpage. Earlier this year, they ran campaigns that leveraged a second stage TDS (victory-leads[.]xyz) that conditionally routed users to different malicious content based on their geo-location (see attached image). We recommend blocking the following TDS domains; doing so will effectively disrupt the attack chains that are conducted by this actor. Currently, only choto[.]click appears to be actively used. We have been tracking this TDS since Spring 2023.

    <Lookalike Domains>
    donga[.]delivery (imitating donga.com - South Korean newspaper company)
    tutorialspoint[.]pics (imitating tutorialspoint.com - video tutorial education service)
    icicibank[.]observer (imitating icicibank.com - Indian banking)
    netflixg[.]com (imitating netflix.com - video streaming service)
    capktalone[.]com (imitating capitalone.com - American banking company)
    cbssportas[.]com (imitating cbssports.com - American sports network)
    betwah[.]de (imitating betway.com - British gambling company)

    <TDS Domains>
    choto[.]click
    choto[.]xyz
    choto[.]store
    victory-leads[.]xyz

    <Fraud Landing Page Domains>
    lotto60[.]com
    joya[.]casino
    tickets[.]love

    #dns #cybersecurity #InfobloxThreatIntel #Infoblox #tds #gambling #scam #lookalike #typosquat #threatintel #cybercrime

  7. Threat actor using lookalike domains that drive through a traffic distribution system (TDS) to illegal gambling and malicious content. This actor runs a TDS using a few different domains, including choto[.]xyz and choto[.]click. The attack chain typically begins when an internet user unknowingly mistypes a website (e.g. dizscord[.]com instead of discord.com). Subsequently, the user is profiled via one or two TDS servers and then conditionally redirected to a fraudulent webpage. Earlier this year, they ran campaigns that leveraged a second stage TDS (victory-leads[.]xyz) that conditionally routed users to different malicious content based on their geo-location (see attached image). We recommend blocking the following TDS domains; doing so will effectively disrupt the attack chains that are conducted by this actor. Currently, only choto[.]click appears to be actively used. We have been tracking this TDS since Spring 2023.

    <Lookalike Domains>
    donga[.]delivery (imitating donga.com - South Korean newspaper company)
    tutorialspoint[.]pics (imitating tutorialspoint.com - video tutorial education service)
    icicibank[.]observer (imitating icicibank.com - Indian banking)
    netflixg[.]com (imitating netflix.com - video streaming service)
    capktalone[.]com (imitating capitalone.com - American banking company)
    cbssportas[.]com (imitating cbssports.com - American sports network)
    betwah[.]de (imitating betway.com - British gambling company)

    <TDS Domains>
    choto[.]click
    choto[.]xyz
    choto[.]store
    victory-leads[.]xyz

    <Fraud Landing Page Domains>
    lotto60[.]com
    joya[.]casino
    tickets[.]love

    #dns #cybersecurity #InfobloxThreatIntel #Infoblox #tds #gambling #scam #lookalike #typosquat #threatintel #cybercrime

  8. Threat actor using lookalike domains that drive through a traffic distribution system (TDS) to illegal gambling and malicious content. This actor runs a TDS using a few different domains, including choto[.]xyz and choto[.]click. The attack chain typically begins when an internet user unknowingly mistypes a website (e.g. dizscord[.]com instead of discord.com). Subsequently, the user is profiled via one or two TDS servers and then conditionally redirected to a fraudulent webpage. Earlier this year, they ran campaigns that leveraged a second stage TDS (victory-leads[.]xyz) that conditionally routed users to different malicious content based on their geo-location (see attached image). We recommend blocking the following TDS domains; doing so will effectively disrupt the attack chains that are conducted by this actor. Currently, only choto[.]click appears to be actively used. We have been tracking this TDS since Spring 2023.

    <Lookalike Domains>
    donga[.]delivery (imitating donga.com - South Korean newspaper company)
    tutorialspoint[.]pics (imitating tutorialspoint.com - video tutorial education service)
    icicibank[.]observer (imitating icicibank.com - Indian banking)
    netflixg[.]com (imitating netflix.com - video streaming service)
    capktalone[.]com (imitating capitalone.com - American banking company)
    cbssportas[.]com (imitating cbssports.com - American sports network)
    betwah[.]de (imitating betway.com - British gambling company)

    <TDS Domains>
    choto[.]click
    choto[.]xyz
    choto[.]store
    victory-leads[.]xyz

    <Fraud Landing Page Domains>
    lotto60[.]com
    joya[.]casino
    tickets[.]love

    #dns #cybersecurity #InfobloxThreatIntel #Infoblox #tds #gambling #scam #lookalike #typosquat #threatintel #cybercrime

  9. Phylum reports on the active and ongoing typosquatting campaign targeting PyPI. "This automated typosquat attack carried out over a few short hours in a handful of quick bursts, witnessed the publication of over 500 packages and targeted 16 popular PyPI packages." Phylum describes the attack chain where installing the package triggers malware deployment. No IOC provided but Phylum provides a full package list. 🔗 blog.phylum.io/typosquatting-c

    #PyPi #threatintel #Python #typosquat

  10. Phylum reports on the active and ongoing typosquatting campaign targeting PyPI. "This automated typosquat attack carried out over a few short hours in a handful of quick bursts, witnessed the publication of over 500 packages and targeted 16 popular PyPI packages." Phylum describes the attack chain where installing the package triggers malware deployment. No IOC provided but Phylum provides a full package list. 🔗 blog.phylum.io/typosquatting-c

    #PyPi #threatintel #Python #typosquat

  11. Phylum reports on the active and ongoing typosquatting campaign targeting PyPI. "This automated typosquat attack carried out over a few short hours in a handful of quick bursts, witnessed the publication of over 500 packages and targeted 16 popular PyPI packages." Phylum describes the attack chain where installing the package triggers malware deployment. No IOC provided but Phylum provides a full package list. 🔗 blog.phylum.io/typosquatting-c

    #PyPi #threatintel #Python #typosquat

  12. Phylum reports on the active and ongoing typosquatting campaign targeting PyPI. "This automated typosquat attack carried out over a few short hours in a handful of quick bursts, witnessed the publication of over 500 packages and targeted 16 popular PyPI packages." Phylum describes the attack chain where installing the package triggers malware deployment. No IOC provided but Phylum provides a full package list. 🔗 blog.phylum.io/typosquatting-c

    #PyPi #threatintel #Python #typosquat

  13. README has been crafted for the upcoming Domain Assassin release for both the local and lambda versions with terraforms included for it, and tfenv files plus shell scripts to package the lambda to a zip as well as switch between AWS prod and dev for you easily.

    I have some more tweaks to do before I am comfortable putting it up on Github but I don't see much deviating from here other than the addition of piping #Crowdstrike IOC over API
    #Cybersecurity #InfoSec #AWS #OpenSource #Typosquat

  14. README has been crafted for the upcoming Domain Assassin release for both the local and lambda versions with terraforms included for it, and tfenv files plus shell scripts to package the lambda to a zip as well as switch between AWS prod and dev for you easily.

    I have some more tweaks to do before I am comfortable putting it up on Github but I don't see much deviating from here other than the addition of piping #Crowdstrike IOC over API
    #Cybersecurity #InfoSec #AWS #OpenSource #Typosquat

  15. README has been crafted for the upcoming Domain Assassin release for both the local and lambda versions with terraforms included for it, and tfenv files plus shell scripts to package the lambda to a zip as well as switch between AWS prod and dev for you easily.

    I have some more tweaks to do before I am comfortable putting it up on Github but I don't see much deviating from here other than the addition of piping #Crowdstrike IOC over API
    #Cybersecurity #InfoSec #AWS #OpenSource #Typosquat

  16. Got the official thumbs up from my bosses internally about the Domain Assassin tool I forked from @cybersheepdog Domain Hunter tool. It's working in dev right now on the multiple domains we have as an AWS lambda and piping tickets to Jira in our sandbox. Next step is working with Ops to add the Crowdstrike IoC integration.

    I plan to hopefully open source both the local and terraform versions after sanitizing it end of month. I even have a shell script to switch tfenv files #Infosec #typosquat

  17. Got the official thumbs up from my bosses internally about the Domain Assassin tool I forked from @cybersheepdog Domain Hunter tool. It's working in dev right now on the multiple domains we have as an AWS lambda and piping tickets to Jira in our sandbox. Next step is working with Ops to add the Crowdstrike IoC integration.

    I plan to hopefully open source both the local and terraform versions after sanitizing it end of month. I even have a shell script to switch tfenv files #Infosec #typosquat

  18. Got the official thumbs up from my bosses internally about the Domain Assassin tool I forked from @cybersheepdog Domain Hunter tool. It's working in dev right now on the multiple domains we have as an AWS lambda and piping tickets to Jira in our sandbox. Next step is working with Ops to add the Crowdstrike IoC integration.

    I plan to hopefully open source both the local and terraform versions after sanitizing it end of month. I even have a shell script to switch tfenv files #Infosec #typosquat

  19. We are tracking a large #typosquat campaign targeting the #npm ecosystem. As of this writing, 125 packages have been released in what appears to be an ongoing campaign.

    blog.phylum.io/large-typosquat

    #javascript #opensource #infosec #react #angular #cybersecurity

  20. We are tracking a large #typosquat campaign targeting the #npm ecosystem. As of this writing, 125 packages have been released in what appears to be an ongoing campaign.

    blog.phylum.io/large-typosquat

    #javascript #opensource #infosec #react #angular #cybersecurity

  21. We are tracking a large #typosquat campaign targeting the #npm ecosystem. As of this writing, 125 packages have been released in what appears to be an ongoing campaign.

    blog.phylum.io/large-typosquat

    #javascript #opensource #infosec #react #angular #cybersecurity

  22. We are tracking a large #typosquat campaign targeting the #npm ecosystem. As of this writing, 125 packages have been released in what appears to be an ongoing campaign.

    blog.phylum.io/large-typosquat

    #javascript #opensource #infosec #react #angular #cybersecurity

  23. #Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe

    If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.

    Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO

  24. #Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe

    If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.

    Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO

  25. #Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe

    If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.

    Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO

  26. #Typosquat alert: Someone set up a #fake site that mimics Sophos branding on Sopbos[.]com and that site delivers a #malware #coinminer installer called SophosInstaller.exe

    If you work on a team with a #domain #reputation service or feature, please mark that domain as #malicious.

    Let's all work to render this kind of garbage, and their domain registration, utterly useless. #FAFO

  27. It seams that typosquated packages where prepared to do some #DataExfiltration on developer systems on Crates.io. The packages where successful removed by the Crates.io team.

    blog.phylum.io/rust-malware-st
    #Rust #phylum #typosquat #Malware #infosec

  28. It seams that typosquated packages where prepared to do some #DataExfiltration on developer systems on Crates.io. The packages where successful removed by the Crates.io team.

    blog.phylum.io/rust-malware-st
    #Rust #phylum #typosquat #Malware #infosec

  29. It seams that typosquated packages where prepared to do some #DataExfiltration on developer systems on Crates.io. The packages where successful removed by the Crates.io team.

    blog.phylum.io/rust-malware-st
    #Rust #phylum #typosquat #Malware #infosec

  30. 🚨Phylum's automation reliably identifies new campaigns. We reported on hundreds of packages a few days ago. Today were reporting on RATs being distributed to .

    blog.phylum.io/phylum-discover

  31. 🚨Phylum's automation reliably identifies new #malware campaigns. We reported on hundreds of #typosquat packages a few days ago. Today were reporting on #Golang RATs being distributed to #pypi.

    #infosec #softwaresupplychain #Python #tech

    blog.phylum.io/phylum-discover

  32. 🚨Phylum's automation reliably identifies new #malware campaigns. We reported on hundreds of #typosquat packages a few days ago. Today were reporting on #Golang RATs being distributed to #pypi.

    #infosec #softwaresupplychain #Python #tech

    blog.phylum.io/phylum-discover

  33. As a developer, who would've thought that being bad at typing would end up being a security threat we'd all have to contend with? 😂

  34. As a developer, who would've thought that being bad at typing would end up being a security threat we'd all have to contend with? 😂 #typosquat

  35. As a developer, who would've thought that being bad at typing would end up being a security threat we'd all have to contend with? 😂 #typosquat

  36. As a developer, who would've thought that being bad at typing would end up being a security threat we'd all have to contend with? 😂 #typosquat

  37. [Threatview.io] 🌀⚡Our proactive hunter detected malicious #typosquat domain of #Tor download website spreading #lumma malware

    ⚠️torprogect[.]gives
    🔗Malware hosted on #Gitlab
    gitlab[.]com/makaka1231231/24242

    #DFIR
    #cybersecurity
    #threatintel
    #malware
    #CTI

  38. [Threatview.io] 🌀⚡Our proactive hunter detected malicious #typosquat domain of #Tor download website spreading #lumma malware

    ⚠️torprogect[.]gives
    🔗Malware hosted on #Gitlab
    gitlab[.]com/makaka1231231/24242

    #DFIR
    #cybersecurity
    #threatintel
    #malware
    #CTI

  39. [Threatview.io] 🌀⚡Our proactive hunter detected malicious #typosquat domain of #Tor download website spreading #lumma malware

    ⚠️torprogect[.]gives
    🔗Malware hosted on #Gitlab
    gitlab[.]com/makaka1231231/24242

    #DFIR
    #cybersecurity
    #threatintel
    #malware
    #CTI

  40. [Threatview.io] 🌀⚡Our proactive hunter detected malicious #typosquat domain of #Tor download website spreading #lumma malware

    ⚠️torprogect[.]gives
    🔗Malware hosted on #Gitlab
    gitlab[.]com/makaka1231231/24242

    #DFIR
    #cybersecurity
    #threatintel
    #malware
    #CTI

  41. [Threatview.io] 🌀⚡Our proactive hunter detected malicious #typosquat domain of #Tor download website spreading #lumma malware

    ⚠️torprojectss[.]org
    ⚙️tria.ge/230123-f39thad…
    🌐C2: 77.73.134[.]68

    #DFIR
    #cybersecurity
    #threatintel
    #malware
    #cti

  42. [Threatview.io] 🌀⚡Our proactive hunter detected malicious #typosquat domain of #Tor download website spreading #lumma malware

    ⚠️torprojectss[.]org
    ⚙️tria.ge/230123-f39thad…
    🌐C2: 77.73.134[.]68

    #DFIR
    #cybersecurity
    #threatintel
    #malware
    #cti

  43. [Threatview.io] 🌀⚡Our proactive hunter detected malicious #typosquat domain of #Tor download website spreading #lumma malware

    ⚠️torprojectss[.]org
    ⚙️tria.ge/230123-f39thad…
    🌐C2: 77.73.134[.]68

    #DFIR
    #cybersecurity
    #threatintel
    #malware
    #cti