Threats

Pharming: when the right address sends you to a fake site

Phish Plug ResearchJune 10, 20267 min read

Most phishing needs you to click a bad link. Pharming does not. It poisons the path between a correct address and the real server, so you can type the right domain — or click a genuine bookmark — and still end up on a fake site. That is what makes it unsettling: the address looks right.

How pharming works

When you visit a site, your device translates the name (like bank.com) into a server address using DNS. Pharming tampers with that translation at some point along the way:

  • Device hosts file — malware edits a local file to map a real name to a fake server.
  • Router compromise — a hijacked home router hands out poisoned DNS answers to everything on the network.
  • DNS poisoning — attacks against DNS infrastructure return false answers to many users at once.

Why it is hard to spot

The usual advice — "check the URL" — fails, because the URL is correct. The tells are subtler: a certificate warning on a site that normally has none, small differences in the page, or features that suddenly break. On a properly secured site, a browser certificate error is a serious signal, not something to click through.

Pharming separates the name you trust from the server you reach. HTTPS with a valid certificate is one of the few defences the user can actually see working.

Reducing the risk

  1. Patch and protect routers and devices — change default credentials, keep firmware current.
  2. Use reputable DNS and, where available, protected DNS resolution.
  3. As a brand, enforce HTTPS with HSTS so a downgrade or fake cert is more likely to trigger a warning.
  4. Heed certificate warnings on familiar sites — treat them as stop signs.

While pharming attacks the resolution path, most brand impersonation still runs on lookalike domains and cloaked clones — which Phish Plug detects and takes down.

The takeaway

Pharming is phishing without the fake link: it corrupts the route from a correct address to the real server. Because the URL looks right, the defences shift to infrastructure hygiene, DNS, and HTTPS — and to treating certificate warnings on trusted sites as the red flags they are.

Remove the clones targeting your brand

Run a free clone check on one domain — Phish Plug proves the cloaking and files the takedown.