Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse
Panagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen, Rosa Romero Gómez, Nikolaos Pitropakis, Nick Nikiforakis, Manos Antonakakis
Abstract
Domain squatting is a common adversarial practice where attackers register domain names that are purposefully similar to popular domains. In this work, we study a specific type of domain squatting called "combosquatting," in which attackers register domains that combine a popular trademark with one or more phrases (e.g., betterfacebook[.]com, youtube-live[.]com). We perform the first large-scale, empirical study of combosquatting by analyzing more than 468 billion DNS records - collected from passive and active DNS data sources over almost six years. We find that almost 60% of abusive combosquatting domains live for more than 1,000 days, and even worse, we observe increased activity associated with combosquatting year over year. Moreover, we show that combosquatting is used to perform a spectrum of different types of abuse including phishing, social engineering, affiliate abuse, trademark abuse, and even advanced persistent threats. Our results suggest that combosquatting is a real problem that requires increased scrutiny by the security community.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 1bd85802-6d66-4f55-8975-369f63686137Cited by top-tier papers31
- Skill Squatting Attacks on Amazon AlexaDeepak Kumar, Riccardo Paccagnella, Paul Murley, Eric Hennenfent et al.USENIX Security 2018 · 177 citations
- Catching Phishers By Their Bait: Investigating the Dutch Phishing Landscape through Phishing Kit DetectionHugo L. J. Bijmans, Tim M. Booij, Anneke Schwedersky, Aria Nedgabat et al.USENIX Security 2021 · 61 citations
- You Are Who You Appear to Be: A Longitudinal Study of Domain Impersonation in TLS CertificatesRichard Roberts, Yaelle Goldschlag, Rachel Walter, Taejoong Chung et al.CCS 2019 · 52 citations
- Compromised or Attacker-Owned: A Large Scale Classification and Study of Hosting Domains of Malicious URLsRavindu De Silva, Mohamed Nabeel, Charith Elvitigala, Issa Khalil et al.USENIX Security 2021 · 45 citations
- Mobile App SquattingYangyu Hu, Haoyu Wang, Ren He, Li Li et al.WWW 2020 · 44 citations
Builds on3
- PREDATOR: Proactive Recognition and Elimination of Domain Abuse at Time-Of-RegistrationShuang Hao, Alex Kantchelian, Brad Miller, Vern Paxson et al.CCS 2016 · 133 citations
- Dial One for Scam: A Large-Scale Analysis of Technical Support ScamsNajmeh Miramirkhani, Oleksii Starov, Nick NikiforakisNDSS 2017 · 116 citations
- All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS RecordsDaiping Liu, Shuai Hao, Haining WangCCS 2016 · 91 citations
Related papers
- Characterizing and Mitigating Phishing Attacks at ccTLD ScaleGiovane C. M. Moura, Thomas Daniels, Maarten Bosteels, Sebastian Castro et al.CCS 2024 · 7 citations
- The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500Boladji Vinny Adjibi, Athanasios Avgetidis, Manos Antonakakis, Michael D. Bailey et al.NDSS 2025
- Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed DomainsDaiping Liu, Zhou Li, Kun Du, Haining Wang et al.CCS 2017 · 60 citations
- The Wolf of Name Street: Hijacking Domains Through Their NameserversThomas Vissers, Timothy Barron, Tom van Goethem, Wouter Joosen et al.CCS 2017 · 44 citations
- Exposing the Roots of DNS Abuse: A Data-Driven Analysis of Key Factors Behind Phishing Domain RegistrationsYevheniya Nosyk, Maciej Korczynski, Carlos Gañán, Sourena Maroofi et al.CCS 2025 · 1 citation
