A security technician is investigating a series of compromised user credentials in the accounting department. The investigation reveals that affected employees attempted to navigate to the corporate vendor portal at `vendorportal.com`, but accidentally mistyped the web address as `venderportal.com`. The misspelled website presented an identical mirrored login interface that captured the employees' domain credentials. Which of the following social engineering attack types best describes this threat?
- TyposquattingAnswer
- BSpear phishing
- CWatering hole attack
- DPretexting
Answer
Typosquatting
Typosquatting (also known as URL hijacking) is a form of social engineering where an attacker registers domain names that are common misspellings of legitimate websites. When users accidentally mistype the URL, they are directed to a malicious site designed to steal credentials or deliver malware.
Step-by-Step Solution
Key Concept
Typosquatting (URL Hijacking)
Estimated Time:1m 0s