In the past, we came through a number of Phishing campaigns where the attackers using Valid TLD itself for phishing and the Punycode attack demonstrated by Xudong Zheng.Now hackers find a new way innovative method to create believable URL’s and targeting mobile users, specifically Facebook users.

A legitimate website’s name is followed by a series of hyphens to let the real domain name hide well beyond the right border of the address tab.

The company bring the next examples of the fraudulent URLs, with small modifications to mitigate the readers’ risks: As we see, the crooks are impersonating such popular services as Facebook, Comcast, Craigslist, Offer Up, and i Cloud.

In case the real domain doesn’t hide, words like “login”, “confirm”, or “viewmessage” are added, as seen above.

Why Facebook is the main target, Phish Labs explain trough credentials reuse.