Official Member Of
Trusted Copyright Removal Program
Back to Blogs

Beyond Typosquatting: Combolist Domains, Homoglyphs and the Domain Abuse Brands Don't See Coming

Share this Story

Beyond Typosquatting: Combolist Domains, Homoglyphs and the Domain Abuse Brands Don't See Coming

Typosquatting, registering a misspelled version of a brand's domain, is the domain abuse most brands already watch for, but two harder-to-catch tactics cause comparable or greater damage: homoglyph domains, which use visually similar characters from other alphabets to create a domain that looks nearly identical to the real one, and combolist-driven domains, which are set up specifically to harvest credentials that get bundled into lists used for further attacks across the web. Both tend to go undetected by monitoring built only to catch obvious spelling variations.

Why Typosquatting Alone Is Not Enough to Monitor For

Most domain monitoring tools and internal checks are built around the most obvious threat: a domain that misspells the brand name in a way a human might type by accident, like an extra letter or a swapped character, the exact tactic broken down in typosquatting: the domain fraud tactic most brands don't discover until it's too late. This is a real and common tactic, but it is also the easiest one to defend against, since brands can register the most likely misspellings themselves and monitoring tools can flag new registrations that are simple character edits away from the real domain. The tactics that cause the most damage today are the ones designed specifically to get past this kind of monitoring.

Homoglyph Domains: Threats That Look Identical, Not Just Similar

A homoglyph attack uses characters from a different alphabet or character set that render as visually identical, or nearly identical, to the letters in a brand's real domain. Certain Cyrillic characters, for example, are visually indistinguishable from Latin letters at normal reading size, which means a domain can be registered that looks exactly like the real brand's domain to a human eye while being an entirely different string of characters to a browser and a security system.

This matters because standard typosquatting monitoring, which looks for domains that are a small character edit away from the real one using the same alphabet, often misses homoglyph domains entirely, since the visual similarity does not correspond to a simple text-based similarity a basic monitoring rule would catch. A brand relying only on monitoring misspellings in its own alphabet can have a homoglyph domain running an active phishing campaign for months without detection, the same blind spot covered in the domain portfolio audit: how to find every look-alike site already live against your brand.

Combolist Domains: Built for Credential Harvesting, Not Just Impersonation

A combolist is a compiled list of stolen username and password combinations, often gathered from multiple breaches and sold or shared among threat actors. Some fake websites impersonating a brand are not primarily built to sell counterfeit product or run a giveaway scam, they are built specifically to harvest login credentials from customers who believe they are logging into the brand's real account portal, a tactic that increasingly shows up on mobile as covered in fake login pages on mobile: why app-based phishing is outpacing desktop brand protection. Those harvested credentials get added to combolists and used in credential-stuffing attacks against other services, since many people reuse passwords across sites.

This tactic is dangerous for two reasons beyond the immediate phishing harm. First, it generates ongoing damage to customers well beyond the initial phishing interaction, since a harvested credential can be used against unrelated accounts weeks or months later. Second, the brand whose identity was used often has no visibility into this at all, since the harm shows up as fraud on the customer's other accounts rather than as a direct complaint to the brand.

Why These Tactics Are Growing

Both tactics have become more accessible as the tools to execute them have gotten cheaper and easier to use. Homoglyph domain registration requires no special technical skill beyond knowing which characters render similarly, information that is freely available. Combolist markets have grown alongside the broader increase in data breaches, giving credential harvesters both the technical setup and a ready market for what they collect. Brands with a large, engaged customer base that regularly logs into an account portal are attractive targets specifically because of the volume of credentials that can be harvested.

What Effective Monitoring for These Tactics Requires

Catching homoglyph domains requires monitoring that checks for visual similarity, not just character-based similarity, comparing how a domain renders rather than only comparing the literal text string. Catching combolist-oriented fake websites requires monitoring that looks at what a site is actually asking visitors to do, such as flagging login-page-style content that mimics a brand's real account portal, rather than only scanning for brand name usage in the domain or page text.

Remove.tech's monitoring covers domain and website abuse continuously, using bot-powered search and image recognition that extends to visual comparison of site content and branding, which is built to catch the kind of close visual matches that homoglyph domains and credential-harvesting fake login pages rely on to avoid detection. Because scanning runs continuously rather than on a scheduled check, these harder-to-catch tactics can be flagged closer to when they go live rather than after credentials have already been harvested at scale. Brands wanting to see whether either tactic is already live against them can start with a free brand audit.

FAQ

Can a brand register every possible homoglyph variation of its domain defensively?

Not practically. The number of visually similar character combinations across different alphabets makes defensive registration of every variation unrealistic, which is why detection-based monitoring matters more than trying to pre-register every possible lookalike domain.

How would a brand know if its customers' credentials ended up on a combolist?

This is difficult to detect directly without specialized breach monitoring services that scan combolist markets, since the harm typically surfaces as fraud on unrelated accounts rather than as a report back to the original brand. This is part of why prevention through fast domain detection matters more than after-the-fact discovery.

Do homoglyph domains show up in standard WHOIS or domain monitoring searches?

They can be registered and technically discoverable through domain records, but standard monitoring tools built around text-similarity matching to the brand's real domain often do not flag them, since the character strings are genuinely different even though they render similarly. Visual-comparison-based monitoring is needed to catch these reliably.

Should brands warn customers generally about credential reuse risk tied to their brand?

Yes, particularly for brands with account portals holding payment information. General guidance encouraging unique passwords and multi-factor authentication reduces the downstream damage even if a phishing attempt succeeds in harvesting a password.

Typosquatting is the domain threat every brand already knows to look for, which is exactly why it is no longer where the most damaging activity happens. Homoglyph domains and combolist-driven fake login pages are built specifically to get past monitoring designed for simple misspellings, and catching them requires detection that compares how a site actually looks and behaves, not just how its domain name is spelled.

Protect Your Online Presence

Contact us to safeguard your digital rights effectively.