Hackers have long used lookalike domain names to trick people into visiting malicious websites, but now the threat posed by this tactic could be about to ramp up significantly. That’s because two new domain name extensions have been approved which could lead to an epidemic of phishing attempts.
The two new top-level domains (TLDs) that are causing such consternation are the .zip and .mov extensions. They’ve just been introduced by Google alongside the .dad, .esq, .prof, .phd, .nexus, .foo names.
Sora Shimazaki / Pexels
But the reason why .zip and .mov have generated such controversy is that they impersonate popular file extensions used on Windows and macOS computers. That makes them ripe for malevolent trickery.
Google just made this vital Gmail security tool completely free
FBI disables Russian malware operation targeting foreign governments
This Bing flaw let hackers change search results and steal your files
Many messaging apps and social media websites automatically convert a word ending in a TLD to a website link, meaning that simply telling a friend about a file you want to send them could transform your words into a clickable URL. If a hacker has already registered that URL and is using it for nefarious purposes, your friend could be sent to a harmful website.
Bleeping Computer demonstrated the problem with an example message that read, “First extract the test.zip file and then look for test.mov. Once you have the test.mov file, double-click on it to watch the video.” If a hacker has registered the test.zip and test.mov domains, the message recipient could visit the link in the message and find themselves at risk of downloading an infected file. After all, they might naturally expect that the URL they visit will contain the file they’ve been told to download.
Already being abused
The risk isn’t just theoretical. In fact, cybersecurity firm Silent Push Labs has already seen this kind of sleight of hand out in the wild, with phishing websites being created at microsoft-office.zip and microsoft-office365.zip, which likely attempt to steal user login credentials by impersonating the official Microsoft website. Needless to say, you shouldn’t visit these websites due to the threat they pose.
Potential @Microsoft phishing page abusing the new .zip top-level domain 🚨
Hosted on 151.80.119[.]120 → AS16276 @as16276
— Silent Push Labs (@silentpush_labs) May 13, 2023
While there are plenty of legitimate uses for the .zip and .mov domains, such as for file compression apps or video-streaming platforms, there also appears to be potential for abuse — something that hackers are apparently already taking advantage of.
If you see a link that ends in .zip or .mov and it appears to be linked to a large company, first research that the domain actually belongs to that company before clicking on the link. In fact, you shouldn’t visit any website or download any file sent by someone you do not trust, regardless of whether the .zip or .mov TLDs are involved. Using an antivirus app and a healthy dose of skepticism should go a long way to mitigating the myriad threats online — including from hackers making use of these new domains.