Security insights andplatform updates
Product updates, security research, and launch announcements from the team.

Turning IDN edge cases into typosquats
In 2017, Chromium began showing аррӏе.com, a Cyrillic lookalike of apple.com, as Punycode. Replacing its final е with ө produces аррӏө.com, which Chromium still displays in Unicode with no warning. This post explains why, covering Chromium's checks, the .com registry, and two webmail clients.

Inside Corp MDM, the Android spyware targeting logistics companies
Fake Google Play pages branded as CEVA and TKW Logistics delivered a hidden Android implant that steals new SMS messages, redirects calls, persists across reboots, and accepts remote commands over cleartext HTTP.

Have I Been Squatted achieves SOC 2 Type II compliance
Have I Been Squatted is now SOC 2 Type II compliant, with security controls independently assessed against recognized standards for protecting customer data.

From GAPIUpdate to Odyssey Stealer: inside a macOS wallet-theft chain
The macOS branch of a fake Web3 interview delivered GAPIUpdate.dmg, an Odyssey Stealer build that stole credentials, sessions, and wallets before installing remote tasks and replacing wallet applications.

Building certgrep.sh: a free certificate transparency search engine
The engineering story behind certgrep.sh. An occurrence-only index over certificate transparency, a finite state transducer engine that ran in production for three months, the regex-latency wall that ended it, and the trigram pivot that made the whole thing cheap enough to give away.

From fake interview to signed ClickOnce: inside a three-payload Windows chain
A fake Web3 interview delivered a signed ClickOnce stager on Windows that unpacked two credential stealers and a persistent Go RAT.

Announcing Site Canaries
Site Canaries detect cloned and phishing copies of a production page with a small embedded script, then report flagged hostnames alongside domain findings.

From typosquatting to macOS backdoor via ClickFix and blockchain C2
A macOS ClickFix campaign used typosquatting, clipboard-driven Terminal execution, persistent AppleScript, and a Polygon smart contract as a mutable C2 pointer for backdoor, stealer, RAT, and Ledger replacement modules.

When one RMM tool won't get the job done: inside a phishing operation's infrastructure
A packed carrier-onboarding dropper pulls NetSupport Manager from commodity VPS infrastructure. The same operator box also runs SimpleHelp and ScreenConnect, rotates fresh builds daily, and pivots lures from US carriers to European freight within 24 hours.

Announcing Email Intelligence for Microsoft 365
Email Intelligence ingests domain threat signals from Microsoft 365 mail into Have I Been Squatted lookups. Watchdog adds sender domain blocks in the tenant.

When a trusted trucking email delivers remote access
Attackers used what appears to be a compromised Microsoft 365 account at a US freight carrier, sent Bill of Lading phishing to business contacts, and used a PDF link to an S3-hosted EXE that silently installed a pre-configured N-able RMM agent.

Have I Been Squatted now integrates with Tines
Have I Been Squatted now integrates with Tines, so typosquat permutations, domain analysis data can run directly inside investigation stories.