Research
Unpacking .zip: First Empirical Study of Domain and Filename Confusion Attacks via New gTLDs
Ma, Despotovic et al. provide the first systematic analysis of namespace confusion between filenames and DNS names since the introduction of gTLDs like .zip and .mov. The overlap between file extensions and domain names creates phishing vectors where URLs like update.zip appear to reference local files but resolve to attacker-controlled domains. Quantifies real-world exploitation potential of a threat vector that security practitioners have warned about since 2023.
Source
↳ Follow the thread