Dark Mode

Settings

Capec-505 Detail

Scheme Squatting

Detailed Social Engineering

Parents: 616

Description

An adversary, through a previously installed malicious application, registers for a URL scheme intended for a target application that has not been installed. Thereafter, messages intended for the target application are handled by the malicious application. Upon receiving a message, the malicious application displays a screen that mimics the target application, thereby convincing the user to enter sensitive information. This type of attack is most often used to obtain sensitive information (e.g., credentials) from the user as they think that they are interacting with the intended target application.

Not present

External ID Source Link Description
CAPEC-505 capec https://capec.mitre.org/data/definitions/505.html
REF-434 reference_from_CAPEC https://people.eecs.berkeley.edu/~daw/papers/mobphish-w2sp11.pdf Adrienne Porter Felt, David Wagner, Phishing on Mobile Devices, 2011, University of California, Berkeley

Not present

Not present

Not present

Not present

Not present

Not present