TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Internet, We (Still) Have a Problem With Internationalized Domain Names

2017-04-25 · Read original ↗

ATT&CK techniques detected

2 predictions
T1583.001Domains
95%
"to the threat, so updating to chrome 59 would be a good place to start. as noted by pretty much everyone, internet explorer and safari browsers are not impacted. one potential response that is under your control is your defensive domain purchasing strategy. many phishing schemes …"
T1566.002Spearphishing Link
38%
"in other languages but look almost identical to english letters. by stringing together those codes, you can craft a word that appears to spell out “ apple ” but doesn ’ t. it ’ s a hack, and a ubiquitous one at that. using what ’ s called punycode2 ( rfc 34923 ) — an intermediary…"

Summary

Even URLs that look legitimate can be fake, so train, train, train your users to verify links before they click.