Cybercriminals exploit Cyrillic-Latin lookalikes to spoof sites in Chromium browsers
Attackers are using visually identical Cyrillic and Latin characters to create deceptive URLs that trick users into visiting fake websites.
Key points
- Threat actors are leveraging rare Cyrillic letters that resemble Latin characters to impersonate legitimate web domains.
- The vulnerability affects Chromium-based browsers, allowing spoofed sites to appear identical to trusted destinations.
- This typosquatting technique relies on character confusion rather than software bugs to deceive users.
Cybercriminals are actively exploiting visual similarities between rare Cyrillic and Latin letters to create deceptive website addresses. According to The Register, this technique allows attackers to impersonate popular websites within Chromium-based browsers.
What happened
Attackers are abusing the visual similarity between specific Cyrillic and Latin characters to create fraudulent website addresses. The Register reported that these bad actors are using rare letters that look nearly identical to standard English characters. This allows them to register domain names that appear legitimate at a glance. The deception relies on the user failing to notice the subtle difference in the URL bar.
The issue specifically impacts browsers built on the Chromium engine. Users of these browsers may encounter sites that look like trusted services but are actually controlled by malicious actors. The Register noted that this creates a wide range of typosquatting opportunities for attackers. They can mimic popular brands by swapping a single Latin letter for its Cyrillic counterpart.
This method does not require complex code execution or software vulnerabilities. Instead, it exploits human perception and the way browsers render text. The Register explained that the confusion arises because the characters share the same visual shape. Users often trust the visual appearance of a URL without checking the underlying character set. This makes it easy for attackers to blend in with legitimate traffic.
Why it matters
This type of attack undermines the trust users place in browser address bars. The Register highlighted that typosquatting is a common vector for phishing and credential theft. When users believe they are on a legitimate site, they may enter sensitive information. Attackers can then capture login credentials, payment details, or other personal data.
The prevalence of Chromium-based browsers makes this a widespread risk. Many popular web browsers use the Chromium engine, exposing a large user base to this threat. The Register indicated that the ease of registering these lookalike domains lowers the barrier for entry for attackers. Even casual users can fall victim to these sophisticated visual tricks.
Organizations must recognize that traditional security tools may not catch these domains immediately. Since the sites are technically valid domains, they do not trigger standard malware alerts. The Register suggested that this creates a persistent challenge for security teams. They must educate users to look closely at URLs rather than relying solely on automated protections.
What to watch
- Monitor for new domain registrations that use non-Latin character sets.
- Check browser settings for any indicators of character encoding issues.
- Review phishing reports for mentions of Cyrillic-Latin confusion.
- Inspect URL bars carefully for subtle character differences.
Background: Phishing
Phishing is a social engineering attack where fraudsters impersonate trusted entities to trick you into revealing sensitive information or installing malware. You receive a deceptive message that creates urgency or curiosity, prompting you to click a link or open an attachment. The goal is to harvest credentials, financial data, or access to your devices.
Read the full guide: Phishing Explained: How Attackers Steal Trust and Data
What to do and how to stay safe: Chromium
- Hover over links before clicking to reveal the full URL in the status bar.
- Bookmark frequently visited sites to avoid typing addresses manually.
- Check for HTTPS certificates and verify the domain name matches exactly.
- Once the vendor provides an update, install it promptly to mitigate risks.
Step-by-step guide: Passkeys Explained: Why They Resist Phishing and Where They Fail
General security guidance from the Patch Gazette newsroom. It is not confirmed advice from the organisations named in this story.
Frequently asked questions
Which browsers are affected by this typosquatting issue?
According to The Register, Chromium-based browsers are affected by this issue.
How do attackers create these deceptive websites?
Attackers use rare Cyrillic letters that look like Latin characters to impersonate sites.
Is there a software patch for this vulnerability?
The source material does not mention a specific patch or fix for this issue.




