The attack that starts with a single character
Your brand lives at a domain. So does the attacker’s plan to abuse it.
Swap one letter. Register the .co instead of the .com. Replace an “l” with a “1,” or an “o” with a Cyrillic character that renders identically. Add a hyphen. The result is a domain that looks like yours to anyone reading an email in a hurry — and that’s the whole point. Look-alike domains are the launch pad for credential phishing, invoice fraud, and business email compromise (BEC), where an attacker registers a convincing twin of your domain and emails your customers, your vendors, or your own staff as you.
Registering the domain was never the hard part. The hard part — for defenders — is finding every twin before it’s used, proving which ones are real threats, and getting them taken down. That’s exactly what Critical Path Security delivers with MalDom.
What MalDom is
MalDom (Malicious Domain Detection) is a continuous brand-protection engine, part of the Critical Path Security Léargas platform. We register the domains you want protected — your brand, your customer portals, your executives’ vanity domains — and MalDom watches for imposters around the clock.
It doesn’t just spit out a list of theoretical typos. It verifies which look-alikes actually exist, gathers evidence on each, judges which ones are genuine threats, and prepares the takedown paperwork — with a human’s finger always on the trigger.
Under the hood it’s an automated pipeline: Discover → Enrich → See → Judge → Report.
How Critical Path Security uses MalDom for your organization
MalDom is not a tool we hand you and walk away from. It’s a managed capability our analysts operate on your behalf, tuned to your brands and your customers. Here’s what that looks like day to day.
1. Discover — finding the twins that hide
We generate look-alike permutations of every domain we protect for you, then resolve them against live DNS and surface only the ones that are actually registered. A domain nobody has bought is a footnote; one that exists and points somewhere is a lead.
Most tools stop at single-edit twins — one swapped, inserted, or dropped character. Attackers know this, so they combine two typos to slip through. MalDom runs a deep-scan sweep for two-edit look-alikes that single-edit tooling is structurally blind to. On a real customer domain, this surfaced a live twin differing by two characters — running a hosted business-email suite, fully capable of sending BEC as the real company — that conventional monitoring had never flagged.
We also run Certificate Watch, monitoring certificate-transparency logs so that a newly-issued TLS certificate in your brand space surfaces the moment it appears — often the earliest possible signal that someone is standing up infrastructure to impersonate you. And because a single certificate can carry dozens of names, MalDom tells our analysts exactly which name matched your brand, so an alert is never a mystery.
2. Enrich — turning a name into a dossier
A domain name alone isn’t a decision, so every new discovery is automatically enriched:
- Threat intelligence from VirusTotal and AbuseIPDB — engine detections, reputation, the resolved host’s abuse score and hosting provider — rolled into a single risk rating: high, medium, or low.
- DNS and WHOIS — does it resolve to a real host? Does it have mail (MX) records? A twin that can send mail is a loaded weapon; a parked one is a placeholder. MalDom knows the difference.
- Registration age — a domain registered last week is a very different risk than one a decade old.
3. See — a picture is worth a thousand DNS records
For live discoveries, MalDom captures a screenshot of the rendered page using a hardened, SSRF-guarded headless browser. Our analysts see whether it’s a cloned login page, a parked placeholder, or something unrelated — without ever visiting a hostile site, and without the tool ever being tricked into probing an internal network.
4. Judge — separating the one real threat from the noise
Scale is the real challenge. A single scan can produce hundreds of discoveries; one batch had 888, of which 880 were low-value permutation noise and exactly one was a genuine threat worth reporting.
MalDom’s auto-triage agent does that reasoning automatically. It scores every discovery on the signals that actually predict a threat — how deliberate the look-alike technique is, whether it resolves, whether it can send mail, how freshly it was registered, and any existing threat-intel verdict. Obvious noise is set aside. For the survivors, MalDom brings in AI vision to answer the question that genuinely needs judgment: is this page actually impersonating the brand, or is it a coincidence?
That distinction is where automated tools usually fail — and where our engineering focus goes. A domain named like your client isn’t necessarily attacking your client; it might be an unrelated business that happens to share a name. MalDom’s vision step has caught exactly that, holding back a look-alike before a false report went out naming the customer. The flat pile becomes a short, ranked queue with the real threats on top.
5. Report — takedown paperwork, ready to send
When MalDom identifies genuine impersonation, it drafts the abuse report — addressed to the offending domain’s registrar and hosting provider, with the Anti-Phishing Working Group (APWG) and escalation channels included, and a complete evidence body: the impersonated brand, the technique, DNS and WHOIS records, threat intelligence, and the screenshot.
- Your customers are protected on the copy. When a discovery belongs to one of your customers, MalDom resolves the right contacts and blind-copies them correctly — never handing a roster of their staff to a third party.
- We escalate where evidence is strongest. For domains abusing specific ecosystems, MalDom composes evidence-gated submissions rather than flooding providers with low-confidence noise that would only burn reputation.
The guardrail that earns trust: MalDom never sends on its own
This is worth stating plainly. MalDom will discover, enrich, screenshot, score, and draft — all automatically. But the send is always a human decision. The most the automation ever does is prepare a report and put it in front of a Critical Path Security analyst who reviews it and decides. New capabilities roll out in an observe-only mode first, so our team can watch the system’s judgment before granting it any autonomy at all.
The same restraint runs through the whole system: every action is authenticated, the reconnaissance can never be turned against your own network, and the tool would rather flag a domain for human review than take an irreversible action on a guess.
What this means for your organization
- Nothing slips through. Two-edit twins, freshly-issued certificates, and mail-capable imposters that conventional monitoring misses are all in scope.
- Analysis in minutes, not hours. The hundreds-to-one collapse happens automatically; our analysts work a ranked queue of real threats instead of triaging noise.
- Takedowns go out faster, and correctly. Evidence gathered, report drafted, the right party protected on the copy — a human reviews and sends.
- Your credibility is protected. MalDom is engineered specifically to avoid the false report that names the wrong party — the mistake that costs standing with registrars and trust with customers.
Look-alike domains are cheap for attackers to create and expensive for defenders to chase. Critical Path Security flips that economics — turning a daily manual grind into a continuous, evidence-driven, human-supervised program that protects your brand and your customers.
Protect your brand before an imposter uses it
Talk to Critical Path Security about adding your brand and customer domains to continuous MalDom monitoring.
