Tactic or Technique: Lookalike domain

Attackers register domains that closely resemble legitimate ones to trick you into thinking you're visiting or interacting with a trusted site. These lookalike domains use small visual or typographic changes, like swapping “m” for “rn,” misspelling a brand name, or using characters from other alphabets that look identical.
A link may appear to point to a company you recognize, but it actually leads to a spoofed domain controlled by the attacker. These sites are often convincing replicas of real login pages, built to steal your credentials or trick you into downloading malware.
This technique is common in phishing campaigns and can lead to serious consequences, including account compromise, data theft, or fraud. It also causes damage to the impersonated brand, especially when the domain is used in widespread credential harvesting or malware delivery.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand Impersonation: ShareFile
14d ago
Dec 19th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharefile-f8330307
Brand impersonation: LinkedIn
22d ago
Dec 11th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-linkedin-1a0cde6d
Brand impersonation: DocuSign
23d ago
Dec 10th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-docusign-4d29235c
Link: HR impersonation with suspicious domain indicators and credential theft
30d ago
Dec 3rd, 2025
Sublime Security
/feeds/core/detection-rules/link-hr-impersonation-with-suspicious-domain-indicators-and-credential-theft-f31f8831
Brand impersonation: Google Workspace alert notification
1mo ago
Dec 2nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-google-workspace-alert-notification-143ffbc4
Brand impersonation: DHL
1mo ago
Dec 1st, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-dhl-be4b4ae0
Brand impersonation: Aramco
1mo ago
Nov 20th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-aramco-96e87699
Brand impersonation: Capital One
1mo ago
Nov 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-capital-one-d53848e4
Brand impersonation: Twitter
1mo ago
Nov 13th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-twitter-013c32c2
Link to a domain with punycode characters
1mo ago
Nov 12th, 2025
@ajpc500
/feeds/core/detection-rules/link-to-a-domain-with-punycode-characters-74b3698c
Brand impersonation: Coinbase
1mo ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-coinbase-3dca757a
Vendor impersonation: Thread hijacking with typosquat domain
1mo ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed
Spam/fraud: Predatory journal/research paper request
1mo ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/spamfraud-predatory-journalresearch-paper-request-263ca56b
Brand impersonation: Github
1mo ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-github-9402f92b
Brand impersonation: Meta and subsidiaries
2mo ago
Oct 30th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-meta-and-subsidiaries-e38f1e3b
Brand impersonation: Office 365 mail service
2mo ago
Oct 10th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-office-365-mail-service-51af3d4a
Brand impersonation: PNC
2mo ago
Oct 9th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-pnc-1b5ae4fb
Brand impersonation: FINRA
3mo ago
Oct 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-finra-15c81db4
Brand impersonation: Sublime Security
3mo ago
Oct 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sublime-security-949484ed
Brand impersonation: Netflix
3mo ago
Oct 1st, 2025
min0k
/feeds/core/detection-rules/brand-impersonation-netflix-9f39eea5