{"id":4095,"date":"2025-06-23T13:36:05","date_gmt":"2025-06-23T03:36:05","guid":{"rendered":"https:\/\/gabey.com.au\/gabeyinfo\/?p=4095"},"modified":"2025-06-23T13:53:20","modified_gmt":"2025-06-23T03:53:20","slug":"concealed-yet-obvious-the-tactics-hackers-employ-with-cyrillic-characters-to-mimic-website-urls","status":"publish","type":"post","link":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/concealed-yet-obvious-the-tactics-hackers-employ-with-cyrillic-characters-to-mimic-website-urls\/","title":{"rendered":"Concealed Yet Obvious: The Tactics Hackers Employ with Cyrillic Characters to Mimic Website URLs"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">[Part 1 of 3]<\/h4>\n\n\n\n<style type=\"text\/css\">\n<!--\n\n.prisna-gwt-align-left {\n\ttext-align: left !important;\n}\n.prisna-gwt-align-right {\n\ttext-align: right !important;\n}\n\n\n\nbody {\n\ttop: 0 !important;\n}\n.goog-te-banner-frame {\n\tdisplay: none !important;\n\tvisibility: hidden !important;\n}\n\n#goog-gt-tt,\n.goog-tooltip,\n.goog-tooltip:hover {\n\tdisplay: none !important;\n}\n.goog-text-highlight {\n\tbackground-color: transparent !important;\n\tborder: none !important;\n\tbox-shadow: none !important;\n}\n.translated-rtl font,\n.translated-ltr font {\n\tbackground-color: transparent !important;\n\tbox-shadow: none !important;\n\tbox-sizing: border-box !important;\n\t-webkit-box-sizing: border-box !important;\n\t-moz-box-sizing: border-box !important;\n}\n\n-->\n<\/style>\n\n\n\n<div id=\"google_translate_element\" class=\"prisna-gwt-align-left\"><\/div>\n<script type=\"text\/javascript\">\n\/*<![CDATA[*\/\nfunction initializeGoogleTranslateElement() {\n\tnew google.translate.TranslateElement({\n\t\tmultilanguagePage: true,\n\t\tpageLanguage: \"en\",\n\t\tincludedLanguages: \"af,sq,am,ar,hy,az,eu,bn,bs,bg,my,ca,ceb,ny,zh-CN,zh-TW,co,hr,da,nl,en,eo,et,tl,fi,fr,fy,gl,ka,de,el,gu,ht,ha,haw,iw,hi,hmn,hu,is,ig,id,ga,it,ja,jw,kn,kk,km,ko,ku,ky,lo,la,lv,lt,lb,mk,mg,ms,ml,mt,mi,mr,mn,ne,no,ps,fa,pl,pt,pa,ro,sm,gd,sr,st,sn,sd,si,sk,sl,so,es,su,sw,sv,tg,ta,te,th,tr,uk,ur,uz,vi,cy,xh,yi,yo,zu\"\n\t}, \"google_translate_element\");\n}\n\/*]]>*\/\n<\/script>\n<script type=\"text\/javascript\" src=\"\/\/translate.google.com\/translate_a\/element.js?cb=initializeGoogleTranslateElement\"><\/script>\n\n\n\n<p class=\"wp-block-paragraph\">By&nbsp;Prasanna Abeysekera<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">When \"\u0435\u0445ample-bank.com\" Isn't What It Seems<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Have you ever clicked on a link that appeared to be a familiar website only to discover, too late, that something wasn't quite right? You're not by yourself. Hackers use characters from non-Latin alphabets, including Cyrillic, Greek, or Armenian, that resemble those in Latin-based alphabets to register domains in a tactic known as an IDN homograph attack.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At first glance, what appears to be example-bank.com might not be what it seems. Cyrillic characters, such as \"\u0435\" (Cyrillic) instead of \"e\" (Latin), can trick even experienced users into believing they are visiting the legitimate example-bank.com.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To the untrained eye, there is no visible difference. However, for your web browser and security software, this subtle distinction could go unnoticed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Part one of a three-part series, this article demonstrates how hackers deceive users and bypass basic security measures by utilising language scripts.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What is an IDN Homograph Attack?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">IDN stands for Internationalised Domain Name, which is a system that permits domain names to include characters from a variety of worldwide scripts other than the English alphabet. This is a valuable feature for global access, but it also creates opportunities for exploitation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A homograph is a character that looks identical (or very similar) to another character. In the digital realm, hackers utilise homographs from multiple scripts to register domains that appear legitimate but are different behind the scenes.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Examples of Deceptive Characters:<\/h4>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-center\" data-align=\"center\">Latin<\/th><th class=\"has-text-align-center\" data-align=\"center\">Cyrillic Lookalike<\/th><th class=\"has-text-align-center\" data-align=\"center\">Unicode<\/th><\/tr><\/thead><tbody><tr><td class=\"has-text-align-center\" data-align=\"center\">a <\/td><td class=\"has-text-align-center\" data-align=\"center\">\u0430 <\/td><td class=\"has-text-align-center\" data-align=\"center\">U+0430<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">e<\/td><td class=\"has-text-align-center\" data-align=\"center\">\u0435<\/td><td class=\"has-text-align-center\" data-align=\"center\">U+0435<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">o<\/td><td class=\"has-text-align-center\" data-align=\"center\">\u043e<\/td><td class=\"has-text-align-center\" data-align=\"center\">U+043E<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">p<\/td><td class=\"has-text-align-center\" data-align=\"center\">\u0440<\/td><td class=\"has-text-align-center\" data-align=\"center\">U+0440<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">c<\/td><td class=\"has-text-align-center\" data-align=\"center\">\u0441<\/td><td class=\"has-text-align-center\" data-align=\"center\">U+0441<\/td><\/tr><tr><td class=\"has-text-align-center\" data-align=\"center\">x<\/td><td class=\"has-text-align-center\" data-align=\"center\">\u0445<\/td><td class=\"has-text-align-center\" data-align=\"center\">U+0445<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">So the domain example-bank.com, which uses only Cyrillic characters, can trick even the most savvy users into thinking it's example-bank.com.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Reasons Why This Technique Is Highly Effective<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">There are three main reasons why IDN homograph attacks are effective:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Visual Deception<\/strong>: The average user may not notice slight differences in font rendering. Most people tend to trust what they see.<\/li>\n\n\n\n<li><strong>Browser Rendering<\/strong>: Some browsers display the spoofed version of the domain (e.g., \u0435\u0445ample-bank.com) using Cyrillic characters instead of converting it to its encoded Punycode form (e.g., xn--example-bank-5fd.com). This conversion typically raises a red flag for users.<\/li>\n\n\n\n<li><strong>Security Oversight<\/strong>: Many filters and detection systems do not fully validate script mixing or Unicode normalisation, particularly in lightweight setups.<\/li>\n\n\n\n<li>You can test this yourself by copying and pasting the spoofed domain, \u0435\u0445ample-bank.com, into a <a href=\"https:\/\/www.punycoder.com\/\" data-type=\"link\" data-id=\"https:\/\/www.punycoder.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Punycode converter<\/a>. If the output differs from example-bank.com, you are likely dealing with a deceptive Unicode domain.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">What is the result? Users are directed to phishing or malware sites that appear to be legitimate, where their passwords, personal information, or financial information are discreetly collected.<\/p>\n\n\n\n<p class=\"has-luminous-vivid-amber-background-color has-background wp-block-paragraph\"><em>All domain names mentioned in this article are either fictitious or used solely for illustrative and educational purposes.<br>Any similarity to actual, operational domains \u2014 including well-known websites like apple.com \u2014 is purely coincidental and not intended to imply affiliation, ownership, or endorsement.<br>The examples are provided to help readers understand cybersecurity risks such as IDN homograph attacks.<\/em><\/p>\n\n\n\n<h4 class=\"wp-block-heading\">\ud83e\uddfe Real-World Example: A Spoofed apple.com That Fooled the Eye<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">IDN homograph assaults have transpired in reality, not merely in theory. In 2017, a notable example occurred when security researcher <strong>Xudong Zheng<\/strong> created a domain that closely resembled apple.com in the browser's address bar yet was entirely composed of Cyrillic characters.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Using lookalikes like:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Cyrillic \u0430 (U+0430) for Latin a<\/li>\n\n\n\n<li>Cyrillic \u0440 (U+0440) for Latin p<\/li>\n\n\n\n<li>Cyrillic \u0435 (U+0435) for Latin e<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Zheng created a domain that was rendered visually as apple.com, even though its actual encoded form was xn--80ak6aa92e.com.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\ud83d\udd17 <a href=\"https:\/\/www.xudongz.com\/blog\/2017\/idn-phishing\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read the full analysis: <\/a><em><a href=\"https:\/\/www.xudongz.com\/blog\/2017\/idn-phishing\/\" target=\"_blank\" rel=\"noreferrer noopener\">Phishing with Unicode Domains<\/a><\/em><a href=\"https:\/\/www.xudongz.com\/blog\/2017\/idn-phishing\/\" target=\"_blank\" rel=\"noreferrer noopener\"> by Xudong Zheng<\/a><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He utilised this domain to demonstrate how adversaries could make the spoof name appear genuine in contemporary browsers like Chrome and Firefox. Although raising awareness was Zheng's morally righteous goal, it also demonstrated how readily such a technique could be used as a weapon to steal login credentials, particularly for valuable targets like Apple ID logins.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udd17 Source:<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Zheng's original write-up: <strong>\"Phishing with Unicode Domains\"<\/strong><\/li>\n\n\n\n<li><a href=\"https:\/\/www.xudongz.com\/blog\/2017\/idn-phishing\/\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.xudongz.com\/blog\/2017\/idn-phishing\/<\/a><\/li>\n<\/ul>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>\ud83c\udf10 Click to expand real-world examples of spoofed domains<\/summary>\n<p class=\"wp-block-paragraph\">\ud83e\uddfepaypal.com \u2192 \u0440\u0430\u0443\u0440\u0430l.com<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybercriminals used Cyrillic letters, such as \u0440, \u0430, and \u0443, to mimic the PayPal login page. The spoofed domain was used in phishing emails and credential harvesting attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\ud83d\udc49 Punycode: Resembled something like xn--80aaah6c.com.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cybercriminals have repeatedly targeted PayPal users using homograph domains. A common trick is replacing Latin characters with Cyrillic lookalikes, such as \u0440, \u0430, and \u0443.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2714\ufe0f Documented in domain fuzzing tools like <a href=\"https:\/\/github.com\/elceef\/dnstwist\" target=\"_blank\" rel=\"noreferrer noopener\">DNSTwist<\/a> that detect and generate variants like \u0440\u0430\u0443\u0440\u0430l.com.<br>\u2714\ufe0f <a href=\"https:\/\/cert.pl\/\" target=\"_blank\" rel=\"noreferrer noopener\">CERT Polska<\/a> reported similar spoofing techniques against banking domains.<br>\u2714\ufe0f Validated through <a href=\"https:\/\/www.punycoder.com\/\" data-type=\"link\" data-id=\"https:\/\/www.punycoder.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">punycoder.com<\/a> where entering \u0440\u0430\u0443\u0440\u0430l.com will yield a distinct Punycode value.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\ud83e\uddfe 2. <code>google.com \u2192 g\u043e\u043egle.com<\/code><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this case, both os were replaced with Cyrillic \u043e (U+043E), resulting in a domain that rendered identically in most browsers. Often paired with a valid SSL certificate to display a secure padlock, this technique targeted Gmail and Google Workspace users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Both <code>o<\/code>s are replaced by Cyrillic <code>\u043e<\/code> (U+043E), making it indistinguishable from the real domain in most browsers.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u2714\ufe0f Referenced in <a href=\"https:\/\/itp.cdn.icann.org\/en\/files\/security-and-stability-advisory-committee-ssac-reports\/sac-075-en.pdf\" target=\"_blank\" rel=\"noreferrer noopener\">ICANN SSAC Advisory SAC-075<\/a>, which covers the dangers of homograph spoofing.<\/li>\n\n\n\n<li>\u2714\ufe0f Detected by DNSTwist and similar fuzzing tools<\/li>\n\n\n\n<li>\u2714\ufe0f Included in domain fuzzing and typo-squatting simulations (try in <a href=\"https:\/\/github.com\/elceef\/dnstwist\" target=\"_blank\" rel=\"noreferrer noopener\">dnstwist<\/a>).<\/li>\n\n\n\n<li>\u2714\ufe0f Repeatedly discussed in security blogs and phishing databases<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\ud83e\uddfe 3. <code>amazon.com \u2192 \u0430mazon.com<\/code><br>The first a was swapped with the Cyrillic \u0430. These spoofed domains hosted fake promotions or fake login pages, exploiting user trust in the Amazon brand.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cyrillic <code>\u0430<\/code> mimics the first \"a\" in \"amazon\", frequently seen in phishing simulations and fake promo scams.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u2714\ufe0f Identified in phishing detection systems and VirusTotal submissions<\/li>\n\n\n\n<li>\u2714\ufe0f Flagged in industry red-teaming tools like <a href=\"https:\/\/getgophish.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Gophish<\/a> and <a href=\"https:\/\/github.com\/kgretzky\/evilginx2\" target=\"_blank\" rel=\"noreferrer noopener\">Evilginx<\/a><\/li>\n\n\n\n<li>\u2714\ufe0f Validated with Punycode conversion tools like <a href=\"https:\/\/www.punycoder.com\" target=\"_blank\" rel=\"noreferrer noopener\">punycoder.com<\/a><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\ud83e\uddfe 4. <code>microsoft.com \u2192 micros\u043eft.com<\/code><br>Just one Cyrillic \u043e was enough to create a convincing fake. These domains were used in malware campaigns and fake support pages mimicking Microsoft\u2019s branding and layout.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A single Cyrillic <code>\u043e<\/code> in \u201csoft\u201d creates a deceptive clone of the domain. This method has been used in malware delivery and tech support scams.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\u2714\ufe0f Highlighted in Microsoft's own <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener\">Security Intelligence blog<\/a> and community reports.<\/li>\n\n\n\n<li>\u2714\ufe0f Observed in campaigns impersonating Microsoft\u2019s support desk - often reported via <a href=\"https:\/\/www.scamadviser.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">ScamAdviser<\/a> or flagged in browser warnings.<\/li>\n\n\n\n<li>\u2714\ufe0f Found in real phishing emails where basic filters missed domain name mismatches.<\/li>\n\n\n\n<li>\u2714\ufe0f Detected in phishing feeds such as <a href=\"https:\/\/www.phishtank.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">PhishTank<\/a> or <a href=\"https:\/\/www.openphish.com\/index.html\" data-type=\"link\" data-id=\"https:\/\/www.openphish.com\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\">OpenPhish<\/a> (commercial)<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These examples demonstrate how even minor visual substitutions can bypass user scrutiny and sometimes evade browser and security filters. Modern phishing techniques exploit these similarities and they remain active today.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udee0\ufe0f Want to Try It Yourself?<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use <a class=\"\" href=\"https:\/\/www.punycoder.com\">https:\/\/www.punycoder.com<\/a> to paste spoofed domains and observe the encoded differences - especially when Latin and Cyrillic letters look identical.<\/p>\n<\/details>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udce2 <strong>So yes -<\/strong> <strong>this is not theoretical<\/strong>:<\/h3>\n\n\n\n<h3 class=\"wp-block-heading\">Coming Up Next: What Security Tools Miss<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In Part 2, we will examine how these attacks circumvent many mainstream security tools and why traditional domain filters frequently fail to detect these tactics.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/gabey.com.au\/Legal-Disclaimer.html\" data-type=\"link\" data-id=\"https:\/\/gabey.com.au\/Legal-Disclaimer.html\" target=\"_blank\" rel=\"noreferrer noopener\">Legal Disclaimer<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[Part 1 of 3] By&nbsp;Prasanna Abeysekera When &#8220;\u0435\u0445ample-bank.com&#8221; Isn&#8217;t What It Seems Have you ever clicked on a link that appeared to be a familiar website only to discover, too late, that something wasn&#8217;t quite right? You&#8217;re not by yourself. Hackers use characters from non-Latin alphabets, including Cyrillic, Greek, or Armenian, that resemble those in &hellip; <a href=\"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/concealed-yet-obvious-the-tactics-hackers-employ-with-cyrillic-characters-to-mimic-website-urls\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Concealed Yet Obvious: The Tactics Hackers Employ with Cyrillic Characters to Mimic Website URLs&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":4156,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[155,153,167,156,152,157,151,149,95,165,162,154,164,161,163,159,160,166,150,169,168,158],"class_list":["post-4095","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-and-information-security","tag-browser-security","tag-cybersecurity-awareness","tag-dns-security","tag-domain-name-security","tag-domain-spoofing","tag-email-security","tag-fake-domain-names","tag-idn-homograph-attack","tag-information-security","tag-internationalized-domain-names-idn","tag-internet-safety","tag-phishing-techniques","tag-punycode","tag-security-best-practices","tag-security-exploits","tag-social-engineering","tag-threat-intelligence","tag-unicode-confusables","tag-unicode-phishing","tag-user-interface-deception","tag-web-browser-vulnerabilities","tag-website-spoofing"],"_links":{"self":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/posts\/4095","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/comments?post=4095"}],"version-history":[{"count":0,"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/posts\/4095\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/media\/4156"}],"wp:attachment":[{"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/media?parent=4095"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/categories?post=4095"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gabey.com.au\/gabeyinfo\/index.php\/wp-json\/wp\/v2\/tags?post=4095"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}