Search button
  • About McMaster
    • Home
    • News
    • Research & Innovation
    • Giving to McMaster
    • Working at McMaster
  • Study
    • Undergraduate Programs
    • Graduate Programs
    • Continuing Education
    • Admission Requirements
  • Visit
    • Tours
    • Campus Maps
    • Campus Safety Services
    • Events
  • Connect
    • University Directories
    • Media Inquiries
    • Research Centres & Institutes
    • McMaster Global
    • Alumni

Student Support

  • Campus Safety Services
  • Equity & Inclusion Office
  • IT Support
  • Office of the Registrar
  • Ombuds Office
  • School of Graduate Studies
  • Student Wellness Centre
  • Student Affairs

Tools

  • Academic Calendars
  • Avenue to Learn
  • Campus Maps
  • Faculty and Staff Directory
  • Find an Expert
  • Microsoft Office 365
  • Mosaic
  • Safety App

Faculties

  • DeGroote School of Business
  • Engineering
  • Health Sciences
  • Humanities
  • Science
  • Social Sciences

On Campus

  • Athletics & Recreation
  • Campus Store
  • Housing & Conference Services
  • Hospitality Services
  • Libraries
  • Student Success Centre
McMaster University McMaster logo

Office of the AVP & CTO

  • Home
  • CTO
    • CTO
    • Our People
    • McMaster Women in Tech
  • IT Updates
    • Resources
    • IT News
  • IT Strategy
    • IT Strategy
  • IT Governance
    • IT Governance At McMaster
    • Information Technology Student Advisory Committee
  • IT@Mac
    • UTS
    • Telecom
    • More IT Services
    • McMaster Byte Size
    • Connectivity Newsletter
  • IT Security
  • Contact Us
  1. Home
  2. IT Security Brief: Zip and Mov Domains

IT Security Brief: Zip and Mov Domains

Posted on July 4, 2023
Twitter Facebook LinkedIn

In May 2023, Google introduced eight new top-level domains (TLDs), including .zip and .mov. A TLD is the part of a website address that comes after the dot, such as .com, .org, or .ca. 

ZIP and MOV Domains can be exploited by cyber criminals 

The new .zip and .mov TLDs are being targeted by malicious actors to create deceptive phishing links. These TLDs are associated with common file extensions, making them attractive for exploitation. 

Consider the following example to help understand the issue: 

LEGITIMATE LINK:  https://github.com/kubernetes/kubernetes/archive/refs/tags/v1.27.1.zip  

This is a genuine link to a Zip archive hosted on GitHub, functioning as expected. 

DECEPTIVE LINK: https://github.com/kubernetes/kubernetes/archive/refs/tags/@v1271.zip  

This altered link would not link to GitHub, a trusted website. Instead, it would redirect the user to https[:]//v1271[.]zip, which could be a malicious website using the new .zip domain.

In this example, the deceptive link exploits two factors: 

  1. The @ symbol redirects the user to a new domain. The content before the @ symbol in a standard URL is treated as user info, while everything after the @ symbol is considered the hostname. For example, the URL “https://google.com/gmail/inbox@bing.com” would redirect the user to bing.com instead of google.com. 
  1. Bad actors can use different kinds of forward slash characters (/) that resemble standard forward slashes in a legitimate URL. Notice how the slashes look slightly different in the deceptive link above? This can trick the user into thinking they are clicking on a standard URL. 

What should you do?  

Please remain cautious and exercise good judgment when encountering unfamiliar or suspicious links, particularly those involving the .zip or .mov domains.  

Additionally, take proactive measures to enhance your security, including: 

  • Keep your devices and software up to date. 
  • Use reputable antivirus software. 
  • Practice safe browsing habits. 

If you do fall victim to a phishing scam, do not be embarrassed. Report any and all suspicious email messages to is-spam@mcmaster.ca. If you have opened any suspicious emails, links or attachments please report it to the UTS Service Desk. 

You can also visit McMaster’s Phish Bowl to check out examples of recent phishing attempts reported by members of the McMaster Community. 

Thank you for continuing to help McMaster stay cyber secure.  

 News Category

Related News

News Listing

IT Notice – Increase in ClickFix Social Engineering Attacks

News Category

March 13, 2026

Women in Tech: Spring 2026 Series Highlights McMaster Leaders Shaping the Future of Technology

News Category

March 6, 2026

Innovation Meets Leadership: McMaster and Cisco Spotlight Women’s Health and Technology

News Category

November 6, 2025

Office of the AVP & CTO

Support & Contact

Office of the AVP/CTO

Contact Us
Location: Burke Science Building

Policies

Information Security Policy
Information Storage Guidelines
Mac ID Terms and Conditions of Use

Accessibility

McMaster University is committed to providing websites that are accessible to the widest possible audience. If you require any content on this website in an alternate format, please contact the UTS Service Desk and we will respond as promptly as possible.

If there is an AODA web accessibility issue with this website, please report it to Media Production Services using our AODA bug reporting form.

This website is powered by MacSites

McMaster logo
  • Contact
  • Terms & Conditions
  • Privacy Policy
  • 1280 Main Street West  Hamilton, Ontario  L8S 4L8
  • (905) 525-9140

© 2026 McMaster University