Reαd carefully: how to spot – and avoid – a homoglyph attack
Scam emails are increasingly using psychological tricks, such as using near-identical URLs such as miсrosoft.com
You’ve read the email carefully and it looks legitimate. The link it asks you to click on has none of the usual red flags: there are no weird numbers or extra parts to the URL. You feel safe to proceed.
But if you had looked slightly closer you may have noticed something slightly wrong with one of the characters. Just as in the headline of this piece where instead of “a” we used the Cyrillic “α”.
Fraudsters can use letters from different alphabets to create URLs and email addresses that look almost identical to the real thing, but in reality send anyone who clicks on them to a spoof website or inbox. From there they can harvest personal details to use in their scams.
There are other letters and symbols that are easily switched. Last year tech experts spotted fraudsters using the Japanese hiragana character ん to look like a / in an address designed to look as though it was on Booking.com’s website.
Jake Moore, global security adviser at cybersecurity company ESET, says the fraudsters “love Microsoft” as a company identity to spoof. “A fake site might use the Cyrillic “с” instead of the Latin “c” (miсrosoft v microsoft),” he says.
Moore says this type of fraud – known as a homoglyph attack – is becoming increasingly popular. A homoglyph is a character that looks very similar, or even identical, to another one.
“Most phishing attacks are designed to point people to links these days instead of downloading attachments. Attachments can easily be scanned and caught by security software if malicious,” he says.
“Therefore, criminals need to design their websites where the links look genuine and casually request people to click on them without thinking.”
Marijus Briedis, chief technology officer at NordVPN, says homoglyph attacks “are really more of a psychological trick than a technical one”, because the fraudsters are typically trying to panic you into responding quickly, rather than taking time to check things out.
“The goal is to create a sense of panic so you don’t look too closely at the URL. They’re betting that when we’re in a rush, our brains see what we expect to see,” Briedis says.
It just goes to show that the split-second decision you make when clicking a link is often the most vulnerable part of the whole security chain.”
What it looks like
The real thing. Until you look closely.
You will receive an email or text message suggesting you need to click on a URL or email to sort something out.
Some fonts make substitutions almost impossible to detect. In an email address given in comic sans gill, for example, the Cyrillic a does not look at all out of place.
“We’ve spent years telling people to check the website before trusting it but the problem with this technique is that you can do exactly that and still be fooled as it can look as it should,” says Moore.
If it’s a URL, Moore says typically it will lead to a site that encourages you to enter your credentials for the real site, including your username, password and even a one-time passcode.
What to do
If you are sent a link, take a moment to think rather than reacting immediately.
“If any text, WhatsApp or email is asking you to log in anywhere, it is vital that you independently visit the genuine website rather than trusting the link in front of you to save a few seconds,” says Moore.
And apply the same thinking to email addresses. Type in the address you know to be correct, rather than clicking on a link.
Keep your browser updated. It will flag up suspicious websites, and by keeping it updated it will catch the criminals’ latest workarounds.
Put in place two-factor authentication, or multifactor authentication (2FA or MFA), which means you have two steps to log into a site.
If you find that your details have been compromised, change your passwords immediately. Contact your bank and report the phishing attack to Report Fraud.