Tactic or Technique: Lookalike domain

Attackers register domains that closely resemble legitimate ones to trick you into thinking you're visiting or interacting with a trusted site. These lookalike domains use small visual or typographic changes, like swapping “m” for “rn,” misspelling a brand name, or using characters from other alphabets that look identical.
A link may appear to point to a company you recognize, but it actually leads to a spoofed domain controlled by the attacker. These sites are often convincing replicas of real login pages, built to steal your credentials or trick you into downloading malware.
This technique is common in phishing campaigns and can lead to serious consequences, including account compromise, data theft, or fraud. It also causes damage to the impersonated brand, especially when the domain is used in widespread credential harvesting or malware delivery.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Link to a domain with punycode characters
2h ago
Nov 12th, 2025
@ajpc500
/feeds/core/detection-rules/link-to-a-domain-with-punycode-characters-74b3698c
Brand impersonation: Coinbase
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-coinbase-3dca757a
Vendor impersonation: Thread hijacking with typosquat domain
8d ago
Nov 4th, 2025
Sublime Security
/feeds/core/detection-rules/vendor-impersonation-thread-hijacking-with-typosquat-domain-9c2f38ed
Brand impersonation: Twitter
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-twitter-013c32c2
Spam/fraud: Predatory journal/research paper request
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/spamfraud-predatory-journalresearch-paper-request-263ca56b
Brand impersonation: Github
9d ago
Nov 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-github-9402f92b
Brand impersonation: Meta and subsidiaries
13d ago
Oct 30th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-meta-and-subsidiaries-e38f1e3b
Brand Impersonation: ShareFile
14d ago
Oct 29th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sharefile-f8330307
Brand impersonation: DHL
26d ago
Oct 17th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-dhl-be4b4ae0
Brand impersonation: Office 365 mail service
1mo ago
Oct 10th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-office-365-mail-service-51af3d4a
Brand impersonation: PNC
1mo ago
Oct 9th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-pnc-1b5ae4fb
Brand impersonation: FINRA
1mo ago
Oct 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-finra-15c81db4
Brand impersonation: Capital One
1mo ago
Oct 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-capital-one-d53848e4
Brand impersonation: Sublime Security
1mo ago
Oct 3rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-sublime-security-949484ed
Brand impersonation: Netflix
1mo ago
Oct 1st, 2025
min0k
/feeds/core/detection-rules/brand-impersonation-netflix-9f39eea5
Brand impersonation: Barracuda Networks
1mo ago
Sep 26th, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-barracuda-networks-583fd5eb
Brand impersonation: Okta
1mo ago
Sep 23rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-okta-b7a2989a
Brand impersonation: Wix
1mo ago
Sep 23rd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-wix-45e7b99f
Brand impersonation: Hulu
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-hulu-6833de58
Brand impersonation: UPS
1mo ago
Sep 22nd, 2025
Sublime Security
/feeds/core/detection-rules/brand-impersonation-ups-73b68869