IDN attacks: an almost invisible threat
We all know that the first reflex for avoiding online phishing is to check the website's domain name. At a glance, you can tell that linkedinn.com or gooogle.com are not the real domain names (linkedin.com and google.com, respectively). But cybercriminals have moved up a level to fool users even more effectively. One of these techniques, little known to the general public, is the IDN attack, which lets hackers create fake websites that look identical to the real ones... or almost.
What is an IDN?
An IDN (Internationalized Domain Name) is a domain name that contains special characters from non-Latin alphabets, such as Greek, Arabic, Cyrillic, or accented letters.
Since 2003, IDNs have been created so that more and more people can take advantage of the possibilities of the web in their native language. Thanks to these IDNs, we can register domain names like café.com (with an acute accent), or ехемпле.фр (which means exemple.fr in Cyrillic). Unfortunately, this technological advance has paved the way for malicious abuse: IDN attacks.
How do IDN attacks work?
The idea is relatively simple: an attacker registers a domain name that looks very close to a real domain name, using characters from another alphabet that strongly resemble Latin characters.
For example:
- The domain linkedin.com (which is the official one)
- Versus linkedin.com (which is the fake domain with a letter in the Cyrillic alphabet)
Visually, these two domains appear to be identical, yet they lead to completely different sites, with a single difference: the e (Latin) and the e (Cyrillic).
This type of attack has an even more precise name: attacks that use homograph domain names (homograph attacks), and it is unfortunately almost undetectable to the naked eye. With these IDN attacks, cybercriminals aim to steal login credentials and sensitive, confidential data, spread malware, and generally deceive unsuspecting users.
How can you protect yourself?
Whether you are an ordinary user or a business, there are a few best practices to protect yourself against these IDN attacks.
- Do not click on a link without checking its full URL
- Manually type sensitive web addresses (your bank, for example)
- Train your employees to recognize phishing threats with our training programs at GottaPhish!
> Raise your awareness with GottaPhish training
How can you try generating IDNs?
Whether you are a pentester, CISO, or cybersecurity professional, if you want to test the creation of domain names that look similar to existing domains, here is a tool that can show you how it works:
