Skip to main content

Don’t mistype that URL, as it could lead to malware

researchers use ambient light sensor data to steal browser exhausted man computer problems desk hacking hackers malware frust
Shutterstock
Typo prone? You may want to clean up your act. In a malicious trend known as typosquatting, hackers are now taking advantage of our fast fingers and careless errors, attempting to send malware onto Macs by way of mistyped URLs. According to the security company Endgame, a whopping 300 popular .com sites have been registered in Oman, whose top level domain is .om. But this is only a cover — the .om sites try to load OS X malware known as Genieo onto the Apple devices of unsuspecting users.

Endgame first came across typosquatting when an employee made a typo in “www.netflix.com,” instead typing, “netflix.om.” As Endgame notes, “He did not get a DNS resolution error, which would have indicated the domain he typed doesn’t exist.  Instead, due to the registration of “netflix.om” by a malicious actor, the domain resolved successfully.” Luckily, being an Endgamer, he was able to spot the malware, and “retreated swiftly, avoiding harm.”

Other less savvy users, however, may not have been as lucky. The malware Genieo, Endgame notes, is a rather “common OS X malware/adware variant” that “typically infiltrates the user’s system by posing as an Adobe Flash update.” If the user accepts the update, then Genieo “entrenches itself on the host by installing itself as an extension on various supported browsers (Chrome, Firefox, Safari).”

Typosquatting isn’t all that new — indeed, malware has previously been delivered by way of mistyped addresses. But Endgame does say that it hasn’t previously come across “.om abuse.” So how concerned should we be? The security firm suggests, “Our research also indicates that .om domains associated with the vast majority of major brands may be unregistered. It does not appear that are widely including the .om in their typosquatting mitigation strategies. We strongly recommend doing so.”

So be careful when you’re typing, friends. This is one type of “om” you want nothing to do with.

Editors' Recommendations

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
Don’t buy a cheap GPU in 2024
AMD RX 7600 on a pink background.

I wouldn't spend less than $500 on a new graphics card in 2024. I understand that budget is out of the question for many PC gamers, and I'm not advocating for higher GPU prices going forward. But with the games available today, it just doesn't make sense to settle for a budget GPU that will struggle the moment you take it out of the box.

We got a taste of the problem last year with games like The Last of Us Part One, Resident Evil 4, and Hogwarts Legacy, and the issue is cropping back up again with Horizon Forbidden West. I'm talking about VRAM in modern GPUs. At this point, you're much better off saving up for a more expensive GPU, waiting until the next generation arrives, or digging deep on last-gen options.
Why are you buying a new GPU?
If you pay attention to PC hardware reviews -- particularly the YouTube megamind of reviewers -- you probably already have a sour taste in your mouth for 8GB graphics cards. I get it. I don't agree that 8GB GPUs are completely obsolete, however.

Read more
This one feature could prevent motion sickness, but the Vision Pro doesn’t have it
A divided image shows an Apple Vision Pro and Meta Quest 3.

A new study on virtual reality comfort suggests that some of the best VR headsets have a feature that can help prevent motion sickness. Also known as simulator sickness, the problem is due to a mismatch between what you see in a head-mounted display (HMD) and what your body feels in reality.

It’s well known that gamers prefer higher frames per second (fps) to be able to react more quickly and aim with greater accuracy. According to a recent study, though, a faster refresh rate can also reduce the chances you’ll experience nausea or vertigo after playing a VR game with lots of motion.

Read more
Don’t buy the new MSI Claw handheld — at least not yet
Sonic Superstars running on the MSI Claw.

Don't buy the new MSI Claw handheld, at least not yet. After being announced in January, MSI confirmed that its Windows-based handheld gaming PC would launch on March 8 through the official MSI store -- today, if you're reading this article the day it's published. It says units will start shipping on March 12, with retailers selling them by March 15. MSI has confirmed that there won't be any reviews for the handheld in the near future, unless a media outlet happens to get their hands on what is described as a "very limited" initial run.

Buying any new product before third-party reviewers can poke and prod it is problematic, but the MSI Claw is an even riskier venture. It's not only MSI's first handheld gaming PC ever, but it's also launching with one of Intel's Core Ultra CPUs. We don't know how this chip will perform inside the Claw, and that's a problem for the Claw without any independent reviews.
A new challenger

Read more