
It is common for hackers to lure unsuspecting internet users to websites with URLs that usually include typos, mainly using characters like “.om” because “.om” looks a lot like “.com”, in order to lead them to malware-ridden sites.
Netflix.om is not the same as Netflix.com.
In fact, there has been a huge increase in registrations from Oman over the last month for this very reason.
Information security firm Endgame has published its research into typosquatting malware, which is when people suggest you sign up at web addresses like google.om or googgle.com and redirect those addresses to websites filled with ads, malware, and adware.
Endgame compiled a list of 319 malicious web addresses that specifically use the .om domain. However, since the list was published, many malware web addresses that are installed around very popular websites, such as amazon.om, netflix.om, and yelp.om, no longer lead to a real website. Some listings including yatra.om, baidu.om, and adp.om lead to advertising, but there’s no telling that some of the other web addresses don’t host malicious content that can infect your computer. Many of the malicious websites that Endgame pointed out are now milder and only host advertisements.
“The goal of these pages is simply to generate as much advertising as possible for the bad actors, while trying to keep naive users engaged and/or scared in order to get them to click more links, prolonging their sessions,” Endgame writes on its website.
To combat this issue, companies often take some similar website address names in case people type them incorrectly. For example, googel.com and gooogle.com redirect to google.com. But web developers can't come up with every typo-inspired address.
