Photo via Dushan Hanuska/Flickr (CC BY SA 2.0)

OS X malware creators buy typo versions of popular websites to catch victims

This is pretty insidious.


AJ Dellinger


Published Mar 17, 2016   Updated May 27, 2021, 2:04 am CDT

A typo in a text message might lead to brief embarrassment, but when it comes to domain names, a typo has significantly larger ramifications: For Mac users, missing a single letter in a Web address could land you neck-deep in malware.

Featured Video Hide

According to research from security firm Endgame, several groups are squatting on variants of popular websites, using the .om suffix—the top-level domain for the country Oman—to catch users who miss the “c” when typing in their destination.

Advertisement Hide

The practice, called typosquatting, doesn’t just claim an address in the hope of making a quick buck off of the businesses who may want it—some of these sites are targeting Mac users with malicious software.

While Windows users who visit these sites are simply redirected to advertising network sites that blast them with unwanted ads, Mac users get a popup prompting them to install an Adobe Flash update. The prompt is fake, and clicking it installs adware called Genieo.

Genieo, a common OS X malware, digs into the computer by installing itself as an extension on a variety of supported browsers, including Chrome, Firefox, and Safari. The software can manipulate these browsers in a variety of ways.

Victims of Genieo may notice their homepage change. They may also notice that they start receiving targeted advertising that generates revenue for the developers of the adware.

In the course of its research, Endgame found 334 .om sites exploiting typos in popular Web addresses—319 of which were malicious. Popular sites like Netflix, Gmail, Amazon, Reddit, and GitHub have had their name used as part of the .om scam.

Advertisement Hide

Some sites, like Facebook, Google, and eBay, are targeted with a clever variant—a “c” after the site name but before the suffix., for example, redirects to the ad-laden site. 

It’s not entirely clear how the people behind the typosquatting strategy have been able to snag many of these domains—Oman’s domain-registration process requires verification to claim a commercial domain.

Regardless of how they bypassed that system, their strategy seems to be working: Endgame reported that the sites are receiving enough traffic to cause concerns both for users who accidentally land there and for brands that are now associated with malware and annoying ads.

Macs have become more regular targets of these types of attacks as OS X grows more popular. Recently, the first strain of ransomware for Mac users was spotted in the wild.

H/T Threatpost | Photo via Dushan Hanuska/Flickr (CC BY SA 2.0) 

Share this article
*First Published: Mar 17, 2016, 7:44 am CDT