Leadership1 publisher2 min readPublished
Homoglyph links break the URL check most phishing training teaches
ESET's Jake Moore says a person can inspect a link exactly as they were taught and still be fooled, because one Cyrillic character renders as the Latin one.
The Board Room · Leadership desk
What happened
- Fraudsters build URLs and email addresses out of letters from other alphabets so the address looks like the real one, while the click still lands on a spoof site or inbox.
- Jake Moore of ESET said fraudsters favour Microsoft as an identity to spoof, swapping the Latin c in the company name for a Cyrillic character that looks the same.
- The Guardian reports that last year fraudsters were found using a Japanese hiragana character in place of a forward slash to make an address look as though it sat on Booking.com's site.
- NordVPN's chief technology officer Marijus Briedis said the attack is psychological, designed to panic the target into responding before checking.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- constraint Awareness training that certifies staff in link inspection leaves this path open, so the control register overstates coverage for credential phishing by whatever that module was carrying.
- exposure Any account whose second factor is a code the user types is reachable through the same page that took the password, so the enrolment number in the MFA report measures something other than resistance to this lure.
- decision The replacement control is procedural: staff navigate independently to a known address whenever a message asks them to log in, at a cost of seconds per login and a rule that has to cover genuine messages too.
- contradiction The same article that describes a page harvesting the one-time passcode closes by recommending multifactor authentication, which leaves a reader following the advice in full only partly covered.
The habit under pressure is the one every awareness module can measure: hover over the link and read the address before clicking. Jake Moore, global security adviser at the cybersecurity company ESET, said: "We've spent years telling people to check the website before trusting it but the problem with this technique is that you can do exactly that and still be fooled as it can look as it should." [10]
Moore said the link typically leads to a site that encourages the visitor to enter credentials for the real site, including username, password and even a one-time passcode [11]. The Guardian's remedy list ends with two-factor or multifactor authentication [14]. Both statements are in the same piece, and the second sits inside the first: where the second factor is a code the user types, the page that collected the password collects that too [1].
Whether a substitution can be detected depends on the renderer. The Guardian notes that some fonts make substitutions almost impossible to detect, and that a Cyrillic a in an email address set in comic sans does not look out of place [15]. Detection rates from one mail client's default font therefore do not carry over to another client [2].
Marijus Briedis, chief technology officer at NordVPN, put the operative variable in the user's state. "The goal is to create a sense of panic so you don't look too closely at the URL. They're betting that when we're in a rush, our brains see what we expect to see," Briedis said [9]. Moore's substitute control removes the decision from the moment: "If any text, WhatsApp or email is asking you to log in anywhere, it is vital that you independently visit the genuine website rather than trusting the link in front of you to save a few seconds," he said [12].
Independent navigation is paid for in seconds on every login, by everyone. It only works when it applies to the legitimate messages too, since staff cannot sort genuine from spoofed before they navigate. The Guardian's advice points at the browser, saying an updated browser flags suspicious websites and catches the criminals' latest workarounds [13]. An operator can require a current browser but cannot tune it.
Moore's assessment is that the technique is becoming increasingly popular, and the piece gives no incidence figures [16]. The decade question is whether a person reading characters stays in the control set at all. On this record only two controls work without that reading: independent navigation, and a current browser. The Guardian set a Cyrillic character in place of the Latin a in its own headline to make the point [17].
What to watch
- Any published count of mixed-script phishing domains, which would test Moore's assessment that the technique is becoming more popular.
- Whether phishing simulations start using homoglyph lures specifically, and what detection rates they report by mail client.
- Browser and mail client release notes on how mixed-script addresses are displayed, since that is the one control here a user does not have to read.