An enterprise security operations center (SOC) discovers that several employees mistakenly submitted their corporate domain credentials to an external login portal. The malicious portal was hosted on `login.acme-corp.net`, whereas the legitimate enterprise single sign-on (SSO) portal is `login.acme-corp.com`. The attacker registered the alternate top-level domain to impersonate the enterprise authentication interface. Which of the following social engineering attack vectors was primarily executed by the attacker?
- TyposquattingCevap
- BWatering hole attack
- CSmishing
- DWhaling
Cevap
Typosquatting
Typosquatting (also known as URL hijacking) relies on registering domain names that closely resemble legitimate enterprise domain names—such as changing the top-level domain extension from `.com` to `.net` or inserting common misspellings—to trick users into delivering credentials to an attacker-controlled infrastructure.
Adım Adım Çözüm
Anahtar Kavram
Typosquatting and Domain Impersonation