HomeSecurityDomain typosquatting campaign targeting Sniffies users is out of control

The domain typosquatting campaign targeting Sniffies users is out of control

The gay dating app Sniffies is being impersonated by threat actors hoping to target the site's users with typosquatting domains that push scams and dubious Google Chrome extensions.

See also: Phishing campaign targets Greeks – Steals banking credentials

The domain typosquatting campaign targeting Sniffies users is out of control

In some cases, these illegal domains launch the Apple Music app urging users to purchase a subscription, which in turn would provide a commission to the threat actors.

Sniffies, which launched in 2018, is a web app for gay, bisexual, and transgender men that shows nearby users who are "looking" to have a good time.

See also: Hackers steal millions from healthcare payment processors

A domain typosquatting campaign targeting users of the Sniffies website and app is out of control.

Ethical hacker and security researcher Kody Kinzie shared with BleepingComputer a list of over 50 domains, many of which are spelling variations of the Sniffies brand.

Many of these domains are operated by scammers who hope to catch users who mistype Sniffies.com into a web browser and instead land on the fake domain.

Once they gain access, copycat domains “Sniffies” do one of the following:

  • Pushing the user to install dubious Chrome extensions
  • Launch the “Music” app on Apple devices directly from the web browser
  • Redirecting users to fake technical "support" scam websites.
  • Redirecting users to fake job

In tests by BleepingComputer, one such domain, sniiffies.com, was observed to perform one of the above tasks randomly.

On some visits, it may launch the native Apple Music prompting the user to subscribe for a monthly fee. This is a way for threat actors to earn an affiliate commission:

Sniffies
Sniffies

In other attempts, we were greeted with prompts to install dubious Google Chrome extensions, such as “AdBlock Max” and “Movie Database,” among others.

The domain typosquatting campaign targeting Sniffies users is out of control

See also: Why is vulnerability management proving so difficult?

These extensions may come with unwanted functionality, such as tracking functionality—we did not review all of the code in these extensions.

When searching for casual encounters online, users are advised to type their website name carefully and ensure they are on the real website.

Some typosquatted sites may go a step further, mimicking the look and feel of the real website, which can make them harder to detect as users suffer from phishing.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS