Google's New .zip and .mov Domains Raise Security Concerns
The Story
Google's release of the new .zip and .mov top level domains sparked a cybersecurity debate because the extensions double as common file formats.
Google made eight new domains generally purchasable in May 2023, and although .zip and .mov were technically created back in 2014, only now could anyone register them.
The core risk comes from automatic linkification, where platforms like Twitter turn any text ending in .zip or .mov into a clickable link, letting attackers register a domain matching a familiar filename such as update.zip and redirect users to malware or phishing.
Researchers at Silent Push Labs found a credential stealing phishing page spoofing a Microsoft Office download, and Bobby Rauch showed how Unicode characters and the URL userinfo delimiter could craft convincing fake links.
Google responded that applications already have mitigations such as Safe Browsing that apply to these domains, while the maintainers of the Public Suffix List declined to remove the extensions.
Security experts remained split, warning that a single employee tricked into installing malware could compromise an entire corporate network.
Google made eight new domains generally purchasable in May 2023, and although .zip and .mov were technically created back in 2014, only now could anyone register them.
The core risk comes from automatic linkification, where platforms like Twitter turn any text ending in .zip or .mov into a clickable link, letting attackers register a domain matching a familiar filename such as update.zip and redirect users to malware or phishing.
Researchers at Silent Push Labs found a credential stealing phishing page spoofing a Microsoft Office download, and Bobby Rauch showed how Unicode characters and the URL userinfo delimiter could craft convincing fake links.
Google responded that applications already have mitigations such as Safe Browsing that apply to these domains, while the maintainers of the Public Suffix List declined to remove the extensions.
Security experts remained split, warning that a single employee tricked into installing malware could compromise an entire corporate network.
Why It Matters
Three years on, the .zip warnings were right about the mechanism and wrong about the scale. Netcraft counted 16,705 registered .zip domains six months after launch, 417 named for installers or updates, and had blocked 56 malicious ones, chiefly fake Microsoft, Google and Steam logins: a standing nuisance for mail filters rather than a flood. Google kept the string. The bigger test is now under way. ICANN's 2026 round, its first since 2012, closed on August 12 with more than 1,600 primary applications at a $227,000 base fee apiece (ICANN). Whether anyone applied for another file extension stays hidden until Reveal Day, due within nine weeks of the close, with the date announced in mid September 2026.
Go Deeper
Read the original reporting at BleepingComputer.
Read Full Story at BleepingComputer →