Homoglyph attacks involve the use of characters that look nearly identical to others, often from different alphabets, to create deceptive online addresses. For example, a Cyrillic 'α' can be used in place of a Latin 'a' in a URL, making it appear legitimate at first glance. This technique allows fraudsters to craft URLs and email addresses that closely mimic real ones, directing users to spoofed websites or inboxes.
Fraudsters leverage homoglyphs to bypass typical security measures. Unlike malicious attachments, which security software can often scan and flag, links require users to make a judgment call. By making links appear genuine, criminals aim to trick users into clicking without careful consideration. This method is becoming more prevalent as phishing attacks shift from attachment-based to link-based tactics.
According to Marijus Briedis, CTO of NordVPN, homoglyph attacks are primarily a psychological trick. The intent is to create a sense of urgency or panic, prompting users to click quickly without scrutinizing the URL. This exploits the tendency for people to see what they expect to see, especially when rushed, making them vulnerable to inadvertently providing personal details on fake sites.
Jake Moore, global security adviser at ESET, notes that fraudsters frequently target major brands like Microsoft, substituting characters such as a Cyrillic 'с' for a Latin 'c'. Another example cited is the use of the Japanese hiragana character 'ん' to resemble a '/' in a URL. These attacks aim to harvest personal information, which can then be used for further scams and fraudulent activities.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Homoglyph attacks are an increasing phishing tactic where fraudsters use characters from different alphabets that look similar to legitimate ones to create deceptive URLs and email addresses. This method bypasses traditional security scans for attachments and exploits human psychology to trick users into clicking malicious links, leading to credential harvesting.