Skip to main content
Network & InfrastructureUpdated September 3, 2026

URL Hijacking

URL hijacking is the family of techniques that capture traffic meant for a legitimate web address by registering or taking over a look-alike one. It covers typosquatting (misspellings), homoglyph domains (look-alike Unicode characters), combosquatting (a brand plus a plausible word) and the takeover of expired domains that still receive links and visitors.

The common thread is that the victim believes they are somewhere they are not. Sometimes the mistake is theirs, as with a typo; more often it is manufactured, as with a phishing link whose domain differs from the real one by a character nobody checks. The destination can be a credential page, a malware download, an ad farm or a redirect that monetises the visit.

URL hijacking versus typosquatting: typosquatting is the misspelling case and the term most people reach for, but it is one technique among several. Homoglyph domains substitute characters that render identically (a Cyrillic а for a Latin a). Combosquatting appends a word (brand-verify, brand-billing). Expired-domain takeover needs no look-alike at all: the real domain lapsed and was re-registered by someone else, inheriting its backlinks and bookmarks.

Defence works on the registration side. Look-alike domains are new, cheap and registered in batches, so newly registered domain feeds, registrar patterns and nameserver clustering catch them before the first victim arrives. Brand monitoring against those feeds is the standard countermeasure.

Example

A company’s old marketing domain expires and is re-registered within hours. Its inbound links from press coverage still work, so a steady trickle of visitors arrives and is redirected to a fake login page for the company’s current site. No typo, no look-alike: the real address was hijacked.

In isMalicious

Look-alike and re-registered domains surface first in the newly registered domain feed at /data/nrd-list, and a domain report shows the registration date, registrar, nameservers and hosting that link one hijacked address to the batch it belongs to.

Frequently Asked Questions

What is URL Hijacking?

URL hijacking is the family of techniques that capture traffic meant for a legitimate web address by registering or taking over a look-alike one. It covers typosquatting (misspellings), homoglyph domains (look-alike Unicode characters), combosquatting (a brand plus a plausible word) and the takeover of expired domains that still receive links and visitors.

How is URL Hijacking related to Typosquatting?

URL Hijacking and Typosquatting are both key concepts in threat intelligence. Typosquatting (also called URL hijacking) registers domains that are slight misspellings of legitimate websites to capture traffic from users who make typing errors. These domains are often used for phishing, malware distribution, or ad fraud.

Related Terms

Put this intelligence to work

Query indexed indicators — IPs, domains, URLs, and hashes — in seconds.

Check any indicator free
← Back to Glossary