Some lookalike domains exploit typing errors. Others are literally indistinguishable from the real thing.
In July 2025, Unit42 researchers documented a phishing campaign that demonstrated just how invisible domain impersonation has become. Attackers had combined character substitutions across multiple fields within a single email: the display name, subject line, and body content all contained Cyrillic and Greek characters replacing their Latin equivalents. The display name “Сonfidеntiаl Ꭲiꮯkеt” looked identical to “Confidential Ticket.” The subject referencing “Finаnꮯiаl Տtаtеmеnt” appeared indistinguishable from “Financial Statement.” Recipients who examined these emails carefully would have seen nothing wrong because, visually, nothing was wrong.
The technique exploiting this visual identity, known as a homoglyph attack or IDN (internationalized domain name) homograph attack, isn’t new. Security researchers first demonstrated the problem in 2005, and in 2017 a researcher named Xudong Zheng registered “аррӏе.com” using entirely Cyrillic characters to show that Chrome, Firefox, and Opera would render it identically to “apple.com.” But the intervening years haven’t solved the problem. They’ve industrialized it.
Security teams have long understood typosquatting as a threat: registering domains with common misspellings and waiting for distracted users to mistype a URL. The defense seemed straightforward: train users to check URLs carefully, register obvious misspellings defensively, and monitor for new registrations targeting your brand. That approach worked reasonably well when lookalike domains relied on human error. But homoglyph attacks exploit something users cannot correct for, no matter how careful they are. The Cyrillic letter “а” and the Latin letter “a” appear the same in virtually every font. To a computer, they are entirely different Unicode characters. To a human eye, they are indistinguishable.
The scale of lookalike domain abuse has grown substantially. Infoblox threat researchers now detect more than 20,000 suspicious lookalike domains weekly, while domain research firm Decode reports over 28,000 domains impersonating major global brands. Defensive registration of obvious misspellings offers limited protection when attackers can draw from Cyrillic, Greek, and other Unicode alphabets to create visually identical substitutions that no reasonable registration strategy could anticipate.
How typosquatting and homoglyph attacks differ
Traditional typosquatting exploits predictable human mistakes. Someone typing quickly might enter “gogle.com” instead of “google.com” or “amazom.com” instead of “amazon.com.” These domains target the gap between what users intend to type and what they actually enter.
Homoglyph attacks operate differently. They exploit the gap between what characters look like and what they actually are. When attackers register “аpple.com” using a Cyrillic “а,” the domain renders as “apple.com” in most contexts. The user isn’t making a mistake—the domain genuinely appears legitimate.
This distinction matters for defense. User training can reduce typosquatting risk by encouraging people to slow down, use bookmarks, or verify URLs before entering credentials. No amount of training helps against homoglyphs because there is nothing visible to catch. A domain constructed entirely from Cyrillic lookalikes will pass visual inspection every time, and security researchers have documented that Microsoft Office applications render these internationalized domain names in their deceptive form rather than revealing the underlying Punycode that would expose the substitution.
The infrastructure behind lookalike abuse
Attackers have industrialized lookalike domain operations. Automated tools generate thousands of permutations for any target domain, and with registration costs under fifteen dollars, threat actors can secure hundreds of variants in an afternoon.
The monetization has evolved as well. Research published by Infoblox in late 2025 found that the threat landscape for parked domains has fundamentally shifted. A decade ago, visiting a typosquatted domain carried roughly a five percent chance of being redirected to malicious content. In experiments conducted over recent months, researchers found that over ninety percent of parked domain visits now result in redirection to scams, malware, or other harmful content. The change stems partly from policy shifts at major advertising platforms that have pushed domain holders toward “direct search” or “zero-click” monetization, where visitors are immediately forwarded through advertising chains rather than shown static parking pages.
These redirect chains have grown sophisticated. Infoblox documented systems that profile each visitor using IP geolocation, device fingerprinting, and cookies, then route traffic differently based on whether the visitor appears to be a security researcher or a genuine victim. Visitors from VPNs might see benign parking pages while residential IP addresses get forwarded to credential harvesting sites or malware downloads. One threat actor identified in the research had established typosquatting domains targeting dozens of major destinations including YouTube, eBay, and Microsoft.
Why brand protection requires automated detection
The combination of industrial-scale registration and invisible homoglyph substitution creates a problem that manual monitoring cannot solve. Defensive registration of every possible variant is economically impractical, and visual review of suspicious domains fails entirely when the deception is character-level rather than pattern-level.
The Unit42 research from mid-2025 illustrates the sophistication now common in these campaigns. In the documented attacks, the email chain bounced through seemingly benign websites before landing on a credential harvesting page protected by a custom CAPTCHA designed to block automated security scanners. The homoglyph manipulation wasn’t limited to domains; it extended throughout the phishing email itself, evading content analysis while appearing legitimate to recipients.
The Bottom Line
For organizations concerned with brand protection, human review catches what humans can see, but homoglyph attacks are specifically designed to be invisible. Detection requires automated systems that analyze domains at the character level, comparing Unicode values rather than rendered appearance, and flag registrations that combine visual similarity with the infrastructure signatures associated with malicious intent. The goal isn’t just finding domains that look like yours. It’s identifying which of those domains are being weaponized before they reach your customers.
Key Takeaways
Unit 42 research identifies over 20,000 newly registered suspicious lookalike domains per week. These include typosquatting variants, homoglyph substitutions, and combosquatting domains that combine brand names with keywords like “login” or “secure.”
A homoglyph attack substitutes visually identical Unicode characters for standard Latin letters — such as Cyrillic “а” for Latin “a.” Unlike typosquatting, which relies on typing mistakes, homoglyph domains can be pixel-identical to the legitimate domain, making them undetectable through visual inspection alone.
Dramatically. Research from Infoblox and Krebs indicates that 90% or more of parked lookalike domains now serve malicious content, a sharp reversal from the era when most sat dormant as speculative registrations. The shift means any lookalike domain should be treated as potentially hostile.
Unit 42 documented a campaign that applied homoglyph substitution not just to the domain name but to the sender display name, email headers, and embedded URLs simultaneously — evading content analysis across multiple layers while appearing legitimate to recipients.
Detection requires automated systems that compare domain registrations at the Unicode character level, matching code points rather than rendered appearance. Visual inspection, whether by humans or screenshot-based tools, will miss substitutions that are designed to be invisible.



