- Conservatives are protesting YouTube’s new harassment rules Wednesday 5:36 PM
- YouTuber’s ‘creepy’ comment about Taylor Swift’s eggs gets ratioed Wednesday 5:31 PM
- Bloomberg razzed for accidentally making an Alexa Fleshlight Wednesday 5:29 PM
- Who is putting cowboy hats on pigeons? Wednesday 4:33 PM
- Scammer reportedly bribed Facebook employee to keep posts up Wednesday 3:36 PM
- The 1975’s singer criticized for ‘Islamophobic’ rant Wednesday 3:22 PM
- Ready to dish out $52K for Apple’s new Mac Pro? Wednesday 3:03 PM
- N.K. Jemisin and Jamal Campbell discuss their new Green Lantern comic, ‘Far Sector’ Wednesday 3:00 PM
- YouTube says it will be harsher on creators with ‘patterns of harassing behavior’ Wednesday 1:15 PM
- Why one senator stopped a vote on net neutrality Wednesday 12:49 PM
- Man reportedly denied refugee status after officials fail to forward email Wednesday 12:09 PM
- ‘Jojo Rabbit’ star to lead Disney+ ‘Home Alone’ reboot Wednesday 12:08 PM
- Beyoncé and Kelly Rowland were harassed by Jagged Edge as teens, Mathew Knowles says Wednesday 11:52 AM
- White nationalist Nick Fuentes is upset MTV aired his white nationalist views Wednesday 11:37 AM
- Juice WRLD had secret drug-littered Instagram, according to his ex-girlfriend Wednesday 11:10 AM
A typo in a text message might lead to brief embarrassment, but when it comes to domain names, a typo has significantly larger ramifications: For Mac users, missing a single letter in a Web address could land you neck-deep in malware.
According to research from security firm Endgame, several groups are squatting on variants of popular websites, using the .om suffix—the top-level domain for the country Oman—to catch users who miss the “c” when typing in their destination.
The practice, called typosquatting, doesn’t just claim an address in the hope of making a quick buck off of the businesses who may want it—some of these sites are targeting Mac users with malicious software.
While Windows users who visit these sites are simply redirected to advertising network sites that blast them with unwanted ads, Mac users get a popup prompting them to install an Adobe Flash update. The prompt is fake, and clicking it installs adware called Genieo.
Genieo, a common OS X malware, digs into the computer by installing itself as an extension on a variety of supported browsers, including Chrome, Firefox, and Safari. The software can manipulate these browsers in a variety of ways.
Victims of Genieo may notice their homepage change. They may also notice that they start receiving targeted advertising that generates revenue for the developers of the adware.
In the course of its research, Endgame found 334 .om sites exploiting typos in popular Web addresses—319 of which were malicious. Popular sites like Netflix, Gmail, Amazon, Reddit, and GitHub have had their name used as part of the .om scam.
It’s not entirely clear how the people behind the typosquatting strategy have been able to snag many of these domains—Oman’s domain-registration process requires verification to claim a commercial domain.
Regardless of how they bypassed that system, their strategy seems to be working: Endgame reported that the sites are receiving enough traffic to cause concerns both for users who accidentally land there and for brands that are now associated with malware and annoying ads.
Macs have become more regular targets of these types of attacks as OS X grows more popular. Recently, the first strain of ransomware for Mac users was spotted in the wild.
AJ Dellinger is a seasoned technology writer whose work has appeared in Digital Trends, International Business Times, and Newsweek. In 2018, he joined Gizmodo as the nights and weekend editor.