An attacker registers a domain name that closely resembles an enterprise's official login portal by altering a single character in the domain URL. The attacker uses this fraudulent domain to host a spoofed site that captures employee credentials when users accidentally mistype the legitimate web address. Which of the following social engineering attack vectors is best illustrated in this scenario?
- TyposquattingAnswer
- BWatering hole attack
- CSpear phishing
- DPretexting
Answer
Typosquatting
Typosquatting (also known as URL hijacking) occurs when an attacker registers common misspellings, character omissions, or visually similar variations of a legitimate domain name to trick users who accidentally mistype the web address into visiting a fraudulent portal.
Step-by-Step Solution
Key Concept
Typosquatting (URL Hijacking)
Estimated Time:1m 0s