https://en.wikipedia.org/wiki/Search_domainAn example:
The attacker posts a message to a forum, chatroom, etc. like:
Download: 2024YourCompanySalaryData.zip
When the user clicks "2024YourCompanySalaryData.zip", it is actually a domain name, and loads that website. This website then asks you to enter your corp credentials, or executes a 0-day on the victim's browser, etc.
The forum doesn't need to allow file downloads (i.e. a real .zip might not even work), and even if it does, client or server side virus scanning doesn't have a .zip to inspect.
The user is less wary of phishing, having never seen the .zip TLD. They assume they are downloading a file.
https://blog.talosintelligence.com/zip-tld-information-leak/