Earlier quoted context omitted.
We see some of this with just normal spear phishing against companies. The "single click" thing is reasonably common, it makes things a bit harder to catch as often the clickthrough will change to whatever is being spoofed in the first place. A homophone ycornbinator.com would serve the malware first time, then next time it would send a permanent redirect. Unique IDs you'll see in things like spam SMS, both to work a…
Thanks for the input. A nit, sorry, but maybe relevant to readers learning a little about anti-phishing: homophones sound the same ('-phone' refers to sound, like telephone) but differ in meaning, such as 'write' and 'right'. I don't know the term for ycombinator.com / ycornbinator.com, which is a real problem, of course.
Typically used via poorly named idn homograph attacks https://en.m.wikipedia.org/wiki/IDN_homograph_attack