Insights That
Drive Revenue News and analysis by John Colascione.
Domain Names

Homoglyph Attacks Turn Lookalike Domain Names Into Convincing Phishing Traps

A homoglyph is a character or sequence of characters that looks identical or very similar to another, despite having a different underlying code value
A homoglyph is a character or sequence of characters that looks identical or very similar to another, despite having a different underlying code value

WEST PALM BEACH, FL – Internet users have been told for years to inspect a website address before clicking a suspicious link. A phishing technique known as a homoglyph attack is designed to defeat that very habit by making a fraudulent domain name appear almost identical to a legitimate one.

The trick relies on characters, letters or combinations of letters that look like something else. A Latin “c,” for example, can be replaced with the visually similar Cyrillic character “с.” To the human eye, microsoft.com and miсrosoft.com may appear identical, but the “с” in the second address is actually the Cyrillic small letter es (Unicode U+0441), making it a completely different domain name.

Example showing how a Cyrillic character can make a domain name appear nearly identical to microsoft.com

The Guardian recently highlighted the technique as an emerging phishing threat, noting that attackers can use visually similar characters from different alphabets inside web and email addresses. Certain fonts and small screens can make the substitutions especially difficult to notice.

A Real Microsoft Phishing Operation

One of the clearest real-world examples surfaced through Microsoft’s investigation of RaccoonO365, a phishing-as-a-service operation that provided criminals with tools for stealing Microsoft 365 credentials.

According to Microsoft, attackers used rnicrosoft.com, replacing the lowercase “m” at the beginning of Microsoft with the letters “r” and “n.” At a glance, particularly in some fonts or on a small screen, the two letters can resemble a single “m.”

Example comparing microsoft.com with the deceptive lookalike domain rnicrosoft.com

This was not a laboratory demonstration. Microsoft said more than 5,000 Microsoft customers across 94 countries had login credentials stolen using RaccoonO365. The service supplied phishing infrastructure and templates that allowed other criminals to imitate legitimate Microsoft communications. Microsoft ultimately obtained a court order allowing its Digital Crimes Unit to seize 338 domains associated with the operation.

Booking.com Attack Hid the Real Domain

Another unusually creative example appeared in 2025 in a phishing campaign impersonating Booking.com. Attackers used the Japanese hiragana character ん, which can resemble combinations such as “/n” or “/~” at a quick glance in some fonts.

The deceptive URL included text resembling a Booking.com address, but the actual registered domain was www-account-booking.com. The hiragana characters helped make portions of the address appear more like directory separators, disguising the true registered domain farther to the right. Victims who continued through the site were ultimately directed to a malicious MSI installer capable of delivering additional malware.

A Fake PayPal Domain Delivered Ransomware

The technique is not new. In 2019, researchers identified a fake PayPal website being used to distribute Nemty ransomware. The fraudulent domain used Unicode characters from another alphabet that could visually render as рayрal.com, closely resembling the legitimate paypal.com.

Behind the scenes, however, that internationalized domain was represented in the ASCII-compatible Punycode form xn--ayal-f6dc.com. The two characters that appear to be lowercase “p” letters in the Unicode version are actually Cyrillic characters.

That distinction is important. A browser does not necessarily display the deceptive Unicode version today. Modern browsers, including Chrome, apply checks to suspicious internationalized domain names and may deliberately show the xn-- Punycode form instead. That is why entering or visiting the domain today may show xn--ayal-f6dc.com in the address bar rather than something resembling paypal.com.

In the 2019 attack, visitors were offered what appeared to be a PayPal cashback application. Those who downloaded and executed the file instead received Nemty ransomware.

Lookalike Domains Are Being Used at Scale

More recent investigations show that lookalike domains are not limited to isolated phishing campaigns. Microsoft’s 2026 investigation into the cybercrime infrastructure provider RedVDS uncovered more than 7,300 IP addresses collectively hosting more than 3,700 homoglyph domains during a single 30-day period. Criminals used the infrastructure to impersonate businesses, hijack email conversations and redirect legitimate payments.

In one documented case, criminals impersonating Bellingham Marine used bellinqham-marine.com instead of bellingham-marine.com. In another case involving Alabama pharmaceutical company H2-Pharma, criminals subtly changed a vendor’s email domain from cheplapharm.com to cheplapharrm.com, adding an extra “r.” Microsoft said H2-Pharma ultimately lost more than $7.3 million.

Browsers Try to Detect the Trick

Internationalized Domain Names allow domain names to contain characters beyond the traditional Latin alphabet. To remain compatible with the Domain Name System, those Unicode characters can be converted into an ASCII-compatible representation called Punycode, which begins with xn--.

Google Chrome applies a series of checks to internationalized domain names and decides whether to display the Unicode version or the Punycode version. Suspicious character combinations, mixed writing systems and domains that closely resemble prominent websites can cause Chrome to display the Punycode address instead.

Those protections help, but they cannot eliminate every form of visual deception. Some attacks, such as rnicrosoft.com, use nothing more than ordinary Latin characters arranged to fool the eye.

The Domain Name Is Now Part of the Attack

For businesses, homoglyph and lookalike attacks create risks beyond someone landing on a fake website. Similar domains can be used for employee credential theft, vendor impersonation, fake invoices and business email compromise, where a nearly identical email domain may be inserted into an existing financial conversation.

HTTPS does not solve the problem. A secure connection means that traffic between the browser and the domain is encrypted. It does not prove that the domain belongs to the company the visitor thinks it does.

Users should avoid logging into important accounts through links delivered by unexpected email or text messages and instead navigate directly to the known website. Businesses should also monitor for domains resembling their brands, use multifactor authentication, maintain email authentication controls and independently verify unexpected requests involving payments or banking information.

The effectiveness of the attack comes from its simplicity. Criminals do not necessarily need to break the real website or compromise the real domain. Sometimes they only need to register something that looks close enough for a recipient to believe it is real.

📌 Enjoyed This Content?

Add STRATEGIC REVENUE as a Google Preferred Source to see more of our business, technology, and digital strategy coverage in Google Search.

Add Strategic Revenue

You can now select the categories you're interested in and receive email updates when new articles are published in only those categories.

Join the Discussion

Your email address will not be published. Required fields are marked *










Related Articles