- Gina Rodriguez slammed for promoting ‘American Dirt’ 4 Years Ago
- Netflix says ‘The Witcher’ is its biggest show. Is it really? 4 Years Ago
- Tulsi Gabbard sues Hillary Clinton for podcast comments 4 Years Ago
- Lizzo reps Beyoncé’s Ivy Park collection in adult-themed TikTok Today 7:58 AM
- Netflix’s ‘Eye for an Eye’ is a fun but messy thriller about revenge Today 7:00 AM
- Which 2020 Democratic candidates post the most cringe? Today 6:30 AM
- The new ‘Hunger Games’ book paints President Snow as a hero—and people are not happy Tuesday 9:03 PM
- Influencer called out for ‘troubling image’ with Kenyan child Tuesday 8:18 PM
- Professor arrested for spending $185K of grant money on iTunes and strippers Tuesday 7:28 PM
- Man cuts his books in half to make them ‘portable,’ spurs online debate Tuesday 6:09 PM
- Fans defend Lana Del Rey after she was mocked for flying commercial Tuesday 5:10 PM
- Lady Gaga fans find alleged new song name in her website’s code Tuesday 4:42 PM
- Barstool Sports deletes anti-union tweets, blog post in settlement Tuesday 3:47 PM
- The ‘can have … as a treat’ meme has come full circle Tuesday 3:09 PM
- Joe Rogan says he’s voting for Bernie Sanders Tuesday 2:54 PM
A typo in a text message might lead to brief embarrassment, but when it comes to domain names, a typo has significantly larger ramifications: For Mac users, missing a single letter in a Web address could land you neck-deep in malware.
According to research from security firm Endgame, several groups are squatting on variants of popular websites, using the .om suffix—the top-level domain for the country Oman—to catch users who miss the “c” when typing in their destination.
The practice, called typosquatting, doesn’t just claim an address in the hope of making a quick buck off of the businesses who may want it—some of these sites are targeting Mac users with malicious software.
While Windows users who visit these sites are simply redirected to advertising network sites that blast them with unwanted ads, Mac users get a popup prompting them to install an Adobe Flash update. The prompt is fake, and clicking it installs adware called Genieo.
Genieo, a common OS X malware, digs into the computer by installing itself as an extension on a variety of supported browsers, including Chrome, Firefox, and Safari. The software can manipulate these browsers in a variety of ways.
Victims of Genieo may notice their homepage change. They may also notice that they start receiving targeted advertising that generates revenue for the developers of the adware.
In the course of its research, Endgame found 334 .om sites exploiting typos in popular Web addresses—319 of which were malicious. Popular sites like Netflix, Gmail, Amazon, Reddit, and GitHub have had their name used as part of the .om scam.
It’s not entirely clear how the people behind the typosquatting strategy have been able to snag many of these domains—Oman’s domain-registration process requires verification to claim a commercial domain.
Regardless of how they bypassed that system, their strategy seems to be working: Endgame reported that the sites are receiving enough traffic to cause concerns both for users who accidentally land there and for brands that are now associated with malware and annoying ads.
Macs have become more regular targets of these types of attacks as OS X grows more popular. Recently, the first strain of ransomware for Mac users was spotted in the wild.
AJ Dellinger is a seasoned technology writer whose work has appeared in Digital Trends, International Business Times, and Newsweek. In 2018, he joined Gizmodo as the nights and weekend editor.