- Who survived the ‘Game of Thrones’ series finale? Sunday 10:21 PM
- Justin Bieber fans are damaging one of Iceland’s top tourist spots Sunday 1:28 PM
- James Charles drops 41-minute response video to Tati Westbrook’s accusations Sunday 1:15 PM
- Watch what happens when this Twitch streamer quits his job on camera Sunday 12:25 PM
- Men are finally sharing their abortion stories Sunday 10:58 AM
- Netflix’s ‘Maria’ is a trigger-happy B-movie Sunday 9:07 AM
- How to stream Money in the Bank 2019 for free Sunday 9:00 AM
- How to watch ‘Game of Thrones’ season 8, episode 6 for free Sunday 8:00 AM
- These ‘Game of Thrones’ houses are gone forever Sunday 7:54 AM
- The 10 best anime movies on Hulu Sunday 7:00 AM
- Vibe TV puts a premium price tag on piracy Sunday 6:00 AM
- Twitter unites in collective confusion over ‘Democrats for Trump’ trending Saturday 2:28 PM
- YouTube star tweets and deletes video of his Black cousin ‘Peanut’ acting as a stool Saturday 1:04 PM
- The ‘Do you wash your legs in the shower’ debate has now escalated to feet Saturday 12:20 PM
- Trump posts a world-class golf score, and the internet laughs at him Saturday 10:46 AM
OS X malware creators buy typo versions of popular websites to catch victims
This is pretty insidious.
A typo in a text message might lead to brief embarrassment, but when it comes to domain names, a typo has significantly larger ramifications: For Mac users, missing a single letter in a Web address could land you neck-deep in malware.
According to research from security firm Endgame, several groups are squatting on variants of popular websites, using the .om suffix—the top-level domain for the country Oman—to catch users who miss the “c” when typing in their destination.
The practice, called typosquatting, doesn’t just claim an address in the hope of making a quick buck off of the businesses who may want it—some of these sites are targeting Mac users with malicious software.
While Windows users who visit these sites are simply redirected to advertising network sites that blast them with unwanted ads, Mac users get a popup prompting them to install an Adobe Flash update. The prompt is fake, and clicking it installs adware called Genieo.
Genieo, a common OS X malware, digs into the computer by installing itself as an extension on a variety of supported browsers, including Chrome, Firefox, and Safari. The software can manipulate these browsers in a variety of ways.
Victims of Genieo may notice their homepage change. They may also notice that they start receiving targeted advertising that generates revenue for the developers of the adware.
In the course of its research, Endgame found 334 .om sites exploiting typos in popular Web addresses—319 of which were malicious. Popular sites like Netflix, Gmail, Amazon, Reddit, and GitHub have had their name used as part of the .om scam.
It’s not entirely clear how the people behind the typosquatting strategy have been able to snag many of these domains—Oman’s domain-registration process requires verification to claim a commercial domain.
Regardless of how they bypassed that system, their strategy seems to be working: Endgame reported that the sites are receiving enough traffic to cause concerns both for users who accidentally land there and for brands that are now associated with malware and annoying ads.
Macs have become more regular targets of these types of attacks as OS X grows more popular. Recently, the first strain of ransomware for Mac users was spotted in the wild.
AJ Dellinger is a seasoned technology writer whose work has appeared in Digital Trends, International Business Times, and Newsweek. In 2018, he joined Gizmodo as the nights and weekend editor.