The attacker generates an address matching the first and last characters of one you use, then sends you a zero-value or dust transfer. It now sits in your wallet's history looking exactly like a familiar counterparty.
People lose funds by copying an address from recent activity instead of from the original source. Since wallets abbreviate addresses in the middle, the substitution is invisible at a glance.
Defence: never copy an address out of transaction history. Copy from the exchange deposit page or a saved contact each time, verify several characters from the middle as well as the ends, and send a small test transfer first for large amounts.
Related: crypto-address, wallet-drainer, dust-attack, block-explorer