Uncategorized

Cybercriminals Use Malicious Cybersquatting Attacks to Distribute Malware and Hijack Data

Digital squatting has evolved from a simple trademark nuisance into a dangerous cybersecurity threat.

In 2025, the World Intellectual Property Organization (WIPO) handled a record-breaking 6,200 domain disputes. This represents a 68% increase since 2020.

Security experts warn that criminal networks are now using fake domains not just to sell them for a profit, but to steal customer data, distribute malware, and destroy brand reputations.

How Squatting Works

Cybercriminals use several deceptive tactics to trick users into visiting fraudulent websites:

  • Typosquatting: Registering common misspellings of popular sites (e.g., gooogle.com).
  • Combosquatting: Adding keywords to legitimate brand names (e.g., netflix-login.com).
  • TLD Squatting: Using different extensions, such as registering a .net or .org version of a famous .com business.
  • Homograph Attacks: Using visually similar characters from different alphabets to create undetectable fakes.

Research from SecPod revealed a 19-fold increase in malicious campaigns between late 2024 and mid-2025.

Their analysis showed that 99% of these squatted domains were used for credential phishing or delivering malware.

The experience of Decodo (formerly Smartproxy) highlights the severity of this issue. Decodo, a leading webdata provider, faced aggressive impersonation by bad actors in China.

Scammers registered domains like smartproxy.org and smartproxy.cn to mimic the legitimate service.

Customers who fell for these clones handed over money for services they never received. Worse, when the fake services failed, angry users blamed the legitimate company, severely damaging Decodo’s trust rating.

“Impersonators don’t just steal money,” said Vytautas Savickas, CEO of Decodo. “Every fake site makes it harder for honest businesses to earn trust.”

Notable High-Profile Domain Disputes

CompanySquatter / DomainOutcome / Details
Teslatesla.comOperated as teslamotors.com for years; eventually acquired tesla.com after a reported multi-million dollar settlement.
TikToktiktoks.comTwo individuals registered the domain for $2,000; ByteDance won the WIPO dispute after a refused $145,000 offer.
Microsoftmikerowesoft.comRegistered by teenager Mike Rowe; settled amicably with an Xbox gift after public backlash against Microsoft.
Amulamuldistributor.comScammers used fake domains to run job and franchise fraud rings from 2018–2020.

Phishing attacks, often launched from these fake domains, cost organizations an average of $4.8 million per breach in 2025.

Victims often unknowingly hand over login credentials or download ransomware, leading to massive financial losses.

Experts urge businesses to stop being reactive. Vaidotas Juknys, CCO at Decodo, advises companies to audit their domain portfolios immediately. Protection strategies include:

  1. Defensive Registration: Buying common misspellings and various extensions (like .io, .ai, and .co.uk) before scammers do.
  2. Monitoring: Using services that scan the web for new domain registrations that look like your brand.
  3. Customer Education: Clearly listing official domains on your website and warning users about known impostors.

In 2026, a company’s domain is its front door. Leaving it unguarded allows criminals to pick the lock, resulting in costs that no business can afford to pay.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Dhivya

Divya is a Senior Journalist at Cyber Security news covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

2 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

4 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

4 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago