Security News > 2022 > September > Gay hookup site typosquatted to push dodgy Chrome extensions, scams

Gay hookup site typosquatted to push dodgy Chrome extensions, scams
2022-09-14 18:15

Gay hookup and cruising web app Sniffies is being impersonated by opportunistic threat actors hoping to target the website's users with typosquatting domains that push scams and dubious Google Chrome extensions.

In some cases, these illicit domains launch the Apple Music app prompting users to buy a subscription, which in turn would earn threat actors a commission.

A domain typosquatting campaign targeting users of Sniffies website and app is rampant.

BleepingComputer did observe some ad-blocking code present in AdBlock Max, but to direct users to an ad-blocker via an invasive advert certainly is "Highly ironic," as Daniel Ferguson, a Google Chrome user points out while reviewing the extension on the Web Store.

To be fair, Google Chrome also has a security warning deterring users from falling for typosquats.

Some typosquatted sites may even go a step further by impersonating the look-and-feel of the real website, which can make them harder to spot with users falling for phishing attacks.


News URL

https://www.bleepingcomputer.com/news/security/gay-hookup-site-typosquatted-to-push-dodgy-chrome-extensions-scams/