Phishing using @-URL trick in DNS .zip domains

With Googles release of the DNS top-level-domains .zip and .mov a new phishing (mitre att&ck T1566) trick is possible as bobbyrsec wrote about.

Example 1  <— FQDN =

Example 2 <— FQDN = right? No, it is Because the @ character describes e.g. the authentication of the URL.

Example 3 <— FQDN =



So doublechecking URLs becomes harder. Using Fido2, Passkeys or password-managers (e.g. with auto-fill becomes more important because they dont fall for that trick and are more phishing-resistant.

