How Lookalike Domain Names Fool Users in Homoglyph Phishing Attacks

How Lookalike Domain Names Fool Users in Homoglyph Phishing Attacks
On this page

A domain name can look exactly right and still belong to an attacker. In a homoglyph attack, criminals register lookalike domain names that swap in characters nearly identical to the real ones. The result defeats the habit most users were taught: check the address before you click.

A homoglyph is a character that looks identical or very similar to another. Its underlying code value is different. For example, the Cyrillic letter “с” can replace a Latin “c” in an address. To the eye, microsoft.com and miсrosoft.com match, yet they are completely different domain names.

How Attackers Build a Convincing Fake Address

Some tricks do not need a foreign alphabet at all. In Microsoft’s investigation of RaccoonO365, a phishing-as-a-service operation, attackers used rnicrosoft.com. The letters “r” and “n” can pass for a single “m” in some fonts or on a small screen.

Close-up of hands typing on a laptop indoors, ideal for business and tech themes
Close-up of hands typing on a laptop indoors, ideal for business and tech themes. Illustrative stock photo via Pexels.

That operation had real victims. Microsoft said more than 5,000 Microsoft customers across 94 countries had login credentials stolen using RaccoonO365. Microsoft later obtained a court order allowing its Digital Crimes Unit to seize 338 domains tied to the operation.

Other attacks hide the true domain inside a longer address. A 2025 campaign impersonating Booking.com used the Japanese hiragana character ん, which can resemble “/n” or “/~” at a glance. The registered domain was actually www-account-booking.com, and victims who kept going received a malicious MSI installer.

Why Internationalized Domains Complicate Detection

Internationalized Domain Names let domains contain characters beyond the Latin alphabet. To work with the Domain Name System, those characters can be converted into an ASCII-compatible form called Punycode, which begins with xn--.

That conversion matters in practice. In 2019, researchers found a fake PayPal site spreading Nemty ransomware. Its domain could render as рayрal.com, but the two “p” characters were Cyrillic, and the Punycode form was xn--ayal-f6dc.com.

Google Chrome now checks internationalized domain names and may show the Punycode version instead. Mixed writing systems and domains that closely resemble prominent websites can trigger that fallback. Those protections help, but they cannot stop an attack like rnicrosoft.com, which uses only ordinary Latin letters.

Lookalike Domains Now Run at Scale

These domains are no longer isolated tricks. Microsoft’s 2026 investigation looked at the cybercrime infrastructure provider RedVDS. It found more than 7,300 IP addresses hosting more than 3,700 homoglyph domains in a single 30-day period.

Criminals used that infrastructure to impersonate businesses, hijack email conversations and redirect payments. In one case, attackers impersonating Bellingham Marine used bellinqham-marine.com. In another, they changed a vendor’s email domain from cheplapharm.com to cheplapharrm.com, and Microsoft said H2-Pharma ultimately lost more than $7.3 million.

What Businesses Should Do About Lookalike Domains

HTTPS does not solve the problem. An encrypted connection proves the traffic is protected, not that the domain belongs to the company a visitor expects.

Users should avoid signing in to important accounts through links in unexpected emails or texts and go directly to the known website instead. Businesses should monitor for domains that resemble their brands and use multifactor authentication. They should also maintain email authentication controls and independently verify unexpected payment or banking requests.

The attack works because it is simple. Criminals do not need to break into the real website or domain. They only need to register something that looks close enough to be believed.