Full Report
Attackers abusing rare Cyrillic and Latin letters to impersonate popular websites
Analysis Summary
# Tool/Technique: Homoglyph Typosquatting (Chromium Bypass)
## Overview
This technique involves using Internationalized Domain Names (IDNs) containing specific Cyrillic and Latin characters to impersonate popular websites. By exploiting logic quirks in how Chromium-based browsers (Chrome, Edge) handle Unicode display, attackers can present a fake URL that appears identical to a legitimate one, bypassing built-in anti-phishing protections.
## Technical Details
- **Type:** Technique (Social Engineering / Impersonation)
- **Platform:** Windows, macOS, Linux, Android (specifically Chromium-based browsers)
- **Capabilities:** URL spoofing, bypassing `SafeToDisplayAsUnicode` checks, bypassing `GetSimilarTopDomain` skeleton matching.
- **First Seen:** Discovery of these specific "breaker" characters reported October 2026; similar techniques date back to 2017.
## MITRE ATT&CK Mapping
- **[TA0001 - Initial Access]**
- **[T1566 - Phishing]**
- **[T1566.002 - Spearphishing Link]**
- **[TA0007 - Discovery]**
- **[T1583.001 - Acquire Infrastructure: Domains]**
## Functionality
### Core Capabilities
- **Visual Deception:** Uses homoglyphs (characters that look identical to others) to create lookalike domains.
- **Punycode Exploitation:** Registers domains in Punycode (e.g., `xn--...`) that the browser renders as Unicode (e.g., `apple.com`).
- **Breaker Characters:** Utilizes specific characters not yet included in browser "blacklist" filters to force the browser to render the entire string as Unicode instead of reverting to Punycode.
### Advanced Features
- **Logic Bypass (SafeToDisplayAsUnicode):** Exploits the "all-or-nothing" nature of Chromium’s check. By including "breaker" characters like **ө** (Cyrillic barred O) or **ƙ** (Latin K with hook), the browser fails to identify the string as a known spoofing attempt.
- **Skeleton Matching Evasion:** Bypasses the `GetSimilarTopDomain()` function. Because characters like **ƙ** lack standard accents/diacritics, they are converted into skeletons with unique combining marks (e.g., `o k ' t a`) that do not match the hardcoded list of popular site skeletons (e.g., `o k t a`).
- **Safety Tip Evasion:** Circumvents browser warnings by ensuring the domain has two or more character changes from the original or by targeting domains with fewer than five characters.
## Indicators of Compromise
### Network Indicators
*Defanged Examples of Research Domains:*
- `aррӏө[.]com` (Punycode: `xn--80a6aa68c8d[.]com`)
- `sрасөх[.]com` (Punycode: `xn--80a5aeq0fr0c[.]com`)
- `oƙta[.]com` (Punycode: `xn--ota-f6a[.]com`)
- `niƙe[.]com` (Punycode: `xn--nie-g6a[.]com`)
- `ínstagarm[.]com` (Safety Tip bypass example)
### Behavioral Indicators
- Navigation to high-traffic sites (banking, social media) where the Punycode version of the URL is visible in network logs or headers despite appearing as Unicode in the UI.
## Associated Threat Actors
- **Phishing Campaign Operators:** General cybercriminals seeking credentials.
- **APT Groups:** Used for targeted initial access via spearphishing.
- **Research Group:** *Have I Been Squatted* (Ian Muscat and Leanne Briffa) - Identified the recent bypasses.
## Detection Methods
- **Browser Monitoring:** Identifying when a browser renders a Punycode domain that translates to a high-value brand.
- **Log Analysis:** Monitoring DNS and HTTP logs for domains starting with `xn--`.
- **YARA Rules:** Can be written to flag specific Punycode strings in email bodies or suspicious URLs.
- **Punycode Translation:** Automated scripts to convert IDNs to ASCII and check against a "gold list" of protected brand names.
## Mitigation Strategies
- **User Education:** Training users to hover over links and be wary of unusual characters, though these specific bypasses make visual detection difficult.
- **Domain Monitoring:** Brands should proactively register common homoglyph variations of their domains or use services to monitor new IDN registrations.
- **Security Software:** Use endpoint protection or email gateways that automatically decode Punycode and perform reputation checks.
- **Browser Updates:** Ensure Chromium browsers are updated to the latest version to receive new character blacklists (e.g., ensuring versions higher than Chrome 154).
## Related Tools/Techniques
- **Punycode:** The standard for representing Unicode in ASCII.
- **Bitsquatting:** Targeting domains one bit-flip away from a major domain.
- **Typosquatting:** Common misspelling of domains (e.g., `gogle.com`).
- **Combosquatting:** Adding keywords to a brand name (e.g., `apple-support.com`).