← All stories
● Covered by 1 source · 1 reportLow impact1 neutral

Homoglyph Attacks Use Similar-Looking Characters to Create Fake URLs and Emails

🔄 Updated 3d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Homoglyph attacks use visually similar characters from different alphabets.
  • Fraudsters create fake URLs and email addresses that appear legitimate.
  • The attacks exploit human psychology and bypass attachment scans.
  • The goal is to harvest personal details from unsuspecting users.

Understanding Homoglyph Attacks

Homoglyph attacks involve the use of characters that look nearly identical to others, often from different alphabets, to create deceptive online addresses. For example, a Cyrillic 'α' can be used in place of a Latin 'a' in a URL, making it appear legitimate at first glance. This technique allows fraudsters to craft URLs and email addresses that closely mimic real ones, directing users to spoofed websites or inboxes.

How They Work

Fraudsters leverage homoglyphs to bypass typical security measures. Unlike malicious attachments, which security software can often scan and flag, links require users to make a judgment call. By making links appear genuine, criminals aim to trick users into clicking without careful consideration. This method is becoming more prevalent as phishing attacks shift from attachment-based to link-based tactics.

Psychological Manipulation

According to Marijus Briedis, CTO of NordVPN, homoglyph attacks are primarily a psychological trick. The intent is to create a sense of urgency or panic, prompting users to click quickly without scrutinizing the URL. This exploits the tendency for people to see what they expect to see, especially when rushed, making them vulnerable to inadvertently providing personal details on fake sites.

Examples and Impact

Jake Moore, global security adviser at ESET, notes that fraudsters frequently target major brands like Microsoft, substituting characters such as a Cyrillic 'с' for a Latin 'c'. Another example cited is the use of the Japanese hiragana character 'ん' to resemble a '/' in a URL. These attacks aim to harvest personal information, which can then be used for further scams and fraudulent activities.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Homoglyph attacks are an increasing phishing tactic where fraudsters use characters from different alphabets that look similar to legitimate ones to create deceptive URLs and email addresses. This method bypasses traditional security scans for attachments and exploits human psychology to trick users into clicking malicious links, leading to credential harvesting.