Homoglyph attacks: how to spot fake URLs using Cyrillic letters
Homoglyph attacks: how to spot fake URLs using Cyrillic letters

Scammers are increasingly using homoglyph attacks, where letters from different alphabets, such as Cyrillic, are substituted in URLs and email addresses to create near-identical lookalikes. These fake links can redirect users to spoofed websites designed to harvest personal details, according to cybersecurity experts.

How homoglyph attacks work

Fraudsters use letters that look similar or identical to Latin characters, such as the Cyrillic "а" instead of "a", to craft URLs that appear legitimate at first glance. A closer inspection of the link in the headline of this article, for example, reveals the substitution, but many users may not notice it.

Jake Moore, global security adviser at cybersecurity company ESET, says fraudsters often target well-known brands like Microsoft. "A fake site might use the Cyrillic 'с' instead of the Latin 'c' (miсrosoft v microsoft)," he explains.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

Last year, tech experts also spotted fraudsters using the Japanese hiragana character ん to mimic a slash in an address designed to look like a Booking.com webpage.

Psychological tricks behind the scams

Moore notes that homoglyph attacks are becoming more popular because most phishing attempts now direct users to links rather than attachments. "Attachments can easily be scanned and caught by security software if malicious," he says. "Therefore, criminals need to design their websites where the links look genuine and casually request people to click on them without thinking."

Marijus Briedis, chief technology officer at NordVPN, describes these attacks as "really more of a psychological trick than a technical one." He says fraudsters aim to create a sense of panic so victims don't scrutinize the URL. "The goal is to create a sense of panic so you don't look too closely at the URL. They're betting that when we're in a rush, our brains see what we expect to see," Briedis adds.

What a homoglyph attack looks like

Victims typically receive an email or text message urging them to click a URL or reply to an email to resolve an issue. The link may lead to a site that prompts users to enter their credentials, including username, password, and even a one-time passcode.

Some fonts make substitutions almost impossible to detect. For instance, in an email address set in Comic Sans, the Cyrillic "а" does not look out of place. Moore warns: "We've spent years telling people to check the website before trusting it but the problem with this technique is that you can do exactly that and still be fooled as it can look as it should."

How to protect yourself

Experts advise taking a moment to think before clicking on any link. Moore recommends: "If any text, WhatsApp or email is asking you to log in anywhere, it is vital that you independently visit the genuine website rather than trusting the link in front of you to save a few seconds."

Apply the same caution to email addresses: type in the address you know to be correct instead of clicking on a link. Keep your browser updated, as it will flag suspicious websites and catch the latest workarounds. Enable two-factor authentication (2FA) or multifactor authentication (MFA) to add an extra step when logging into sites.

If you suspect your details have been compromised, change your passwords immediately, contact your bank, and report the phishing attack to Report Fraud.

Pickt after-article banner — collaborative shopping lists app with family illustration