Tactic or Technique: Lookalike domain

Attackers register domains that closely resemble legitimate ones to trick you into thinking you're visiting or interacting with a trusted site. These lookalike domains use small visual or typographic changes, like swapping “m” for “rn,” misspelling a brand name, or using characters from other alphabets that look identical.
A link may appear to point to a company you recognize, but it actually leads to a spoofed domain controlled by the attacker. These sites are often convincing replicas of real login pages, built to steal your credentials or trick you into downloading malware.
This technique is common in phishing campaigns and can lead to serious consequences, including account compromise, data theft, or fraud. It also causes damage to the impersonated brand, especially when the domain is used in widespread credential harvesting or malware delivery.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Brand impersonation: Chase Bank
12d ago
Mar 2nd, 2026
Sublime Security
Brand impersonation: DocuSign
18d ago
Feb 24th, 2026
Sublime Security
Brand impersonation: Meta and subsidiaries
19d ago
Feb 23rd, 2026
Sublime Security
Brand impersonation: Gusto
24d ago
Feb 18th, 2026
Sublime Security
Brand impersonation: American Express (AMEX)
25d ago
Feb 17th, 2026
Sublime Security
Brand Impersonation: PayPal
29d ago
Feb 13th, 2026
Sublime Security
Brand impersonation: Netflix
1mo ago
Feb 3rd, 2026
min0k
Brand impersonation: Office 365 mail service
1mo ago
Jan 29th, 2026
Sublime Security
Brand impersonation: Aramco
1mo ago
Jan 28th, 2026
Sublime Security
Brand impersonation: AuthentiSign
1mo ago
Jan 21st, 2026
Sublime Security
Brand impersonation: Blockchain[.]com
1mo ago
Jan 21st, 2026
Sublime Security
Vendor impersonation: Thread hijacking with typosquat domain
2mo ago
Jan 12th, 2026
Sublime Security
Brand impersonation: Venmo
2mo ago
Jan 12th, 2026
Sublime Security
Brand impersonation: Wells Fargo
2mo ago
Jan 12th, 2026
Sublime Security
Suspected lookalike domain with suspicious language
2mo ago
Jan 12th, 2026
Sublime Security
Link: Recipient domain in URL path
2mo ago
Jan 12th, 2026
Sublime Security
Brand impersonation: Sublime Security
2mo ago
Jan 12th, 2026
Sublime Security
Brand Impersonation: ShareFile
2mo ago
Jan 12th, 2026
Sublime Security
Brand impersonation: Barracuda Networks
2mo ago
Jan 12th, 2026
Sublime Security
Brand impersonation: Hulu
2mo ago
Jan 12th, 2026
Sublime Security