Tactic or Technique: Lookalike domain

Attackers register domains that closely resemble legitimate ones to trick you into thinking you're visiting or interacting with a trusted site. These lookalike domains use small visual or typographic changes, like swapping “m” for “rn,” misspelling a brand name, or using characters from other alphabets that look identical.
A link may appear to point to a company you recognize, but it actually leads to a spoofed domain controlled by the attacker. These sites are often convincing replicas of real login pages, built to steal your credentials or trick you into downloading malware.
This technique is common in phishing campaigns and can lead to serious consequences, including account compromise, data theft, or fraud. It also causes damage to the impersonated brand, especially when the domain is used in widespread credential harvesting or malware delivery.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: AuthentiSign
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-authentisign-445a8c8b
Brand impersonation: Blockchain[.]com
2d ago
Jan 21st, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-blockchaincom-0d85e555
Vendor impersonation: Thread hijacking with typosquat domain
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed
Brand impersonation: Netflix
11d ago
Jan 12th, 2026
min0k
/feeds/core/detection-rules/brand-impersonation-netflix-9f39eea5
Brand impersonation: Meta and subsidiaries
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-meta-and-subsidiaries-e38f1e3b
Brand impersonation: Silicon Valley Bank
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-silicon-valley-bank-a01f61d9
Brand Impersonation: Stripe
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-stripe-862d4654
Brand impersonation: Sublime Security
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sublime-security-949484ed
Brand impersonation: Venmo
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-venmo-0ab15d4f
Brand impersonation: Wells Fargo
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-wells-fargo-02d7301f
Suspected lookalike domain with suspicious language
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/suspected-lookalike-domain-with-suspicious-language-3674ced0
Link: Recipient domain in URL path
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/link-recipient-domain-in-url-path-de08731f
Brand Impersonation: PayPal
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-paypal-a6b2ceee
Sharepoint link likely unrelated to sender
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/sharepoint-link-likely-unrelated-to-sender-6870f489
Brand Impersonation: ShareFile
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharefile-f8330307
Brand impersonation: Barracuda Networks
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-barracuda-networks-583fd5eb
Brand impersonation: Hulu
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-hulu-6833de58
Brand impersonation: UK government Home Office
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-uk-government-home-office-f35d846a
Brand impersonation: American Express (AMEX)
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-american-express-amex-992a9fa9
Brand impersonation: Bank of America
11d ago
Jan 12th, 2026
Sublime Security
/feeds/core/detection-rules/brand-impersonation-bank-of-america-d2fc6ea1