Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Use ‘rn’ Typo Trick to Impersonate Marriott in New Phishing Attack

Hackers Use ‘rn’ Typo Trick to Impersonate Marriott in New Phishing Attack

Posted on January 25, 2026January 25, 2026 By CWS

A complicated “homoglyph” phishing marketing campaign focusing on prospects of Marriott Worldwide and Microsoft. Attackers are registering domains that substitute the letter “m” with the mix “rn” (r + n), creating pretend web sites that look practically an identical to the true ones.

This method, often called typosquatting or a homoglyph assault, exploits the best way trendy fonts show textual content. In lots of fonts, the letters “r” and “n” are positioned subsequent to one another (rn) look visually indistinguishable from the letter “m” (m).

Hackers depend on this visible trick to bypass your mind’s skill to identify errors. While you look shortly at a URL like rnarriottinternational.com, your mind typically “autocorrects” what it sees, assuming it says “Marriott”.

Latest Campaigns Recognized

Marriott Worldwide Focused

Safety agency Netcraft lately recognized a cluster of malicious domains trying to impersonate the lodge big. These domains are doubtless used to steal loyalty account credentials or private visitor information.

The first area recognized is rnarriottinternational.com.

Attackers have additionally registered variations like rnarriotthotels.com to focus on particular lodge manufacturers.

Microsoft Customers Beneath Hearth

Harley Sugarman, CEO of the safety agency Anagram, highlighted an analogous marketing campaign focusing on Microsoft customers. Phishing emails on this marketing campaign use the area rnicrosoft.com to ship pretend safety alerts or bill notifications.

These emails mimic the official Microsoft brand, tone, and format.

The assault is especially harmful on cellular units, the place small screens make the “rn” vs. “m” distinction nearly inconceivable to see.

Indicators of Compromise (IOCs)

The next domains have been flagged as malicious. Safety groups ought to block these instantly, and customers ought to be cautious of any hyperlinks directing to them.

Phishing DomainImpersonated ServiceTyposquatting TechniqueDetection Difficultyrnarriottinternational.comMarriott Worldwide‘m’ changed with ‘rn’Vital rnarriotthotels.comMarriott Resorts‘m’ changed with ‘rn’Criticalrnicrosoft.comMicrosoft 365 / Login‘m’ changed with ‘rn’Excessive (Cell)micros0ft.comMicrosoft‘o’ changed with ‘0’Mediummicrosoft-support.comMicrosoft SupportHyphenation / SuffixLow

How you can Keep Secure

Broaden the Sender Deal with: On cellular e mail apps, faucet the sender’s title to disclose the total e mail handle. Look carefully for the “rn” trick.

Hover Earlier than You Click on: On a pc, hover your mouse cursor over hyperlinks with out clicking to see the precise vacation spot URL.

Handbook Entry: If you happen to obtain an pressing e mail a few lodge reserving or account reset, don’t click on the hyperlink. Open a browser and sort marriott.com or microsoft.com your self.

Use Password Managers: A password supervisor won’t auto-fill your credentials on a pretend web site like rnicrosoft.com as a result of it acknowledges that the area is completely different from the true one.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Attack, Hackers, Impersonate, Marriott, Phishing, Trick, Typo

Post navigation

Previous Post: CISA Warns of Critical VMware vCenter RCE Vulnerability Now Exploited in Attacks
Next Post: Microsoft Investigating Boot Failure Issues With Windows 11, version 25H2 Following January Update

Related Posts

Threats Actors Weaponize ScreenConnect Installers to Gain Initial Access to Organizations Threats Actors Weaponize ScreenConnect Installers to Gain Initial Access to Organizations Cyber Security News
APT36 Malware Campaign Targeting Windows LNK Files to Attack Indian Government Entities APT36 Malware Campaign Targeting Windows LNK Files to Attack Indian Government Entities Cyber Security News
Threat Actors Weaponizes LNK Files to Deploy RedLoader Malware on Windows Systems Threat Actors Weaponizes LNK Files to Deploy RedLoader Malware on Windows Systems Cyber Security News
Critical GoAnywhere MFT Platform Vulnerability Exposes Enterprises to Remote Exploitation Critical GoAnywhere MFT Platform Vulnerability Exposes Enterprises to Remote Exploitation Cyber Security News
HubSpot’s Jinjava Engine Vulnerability Exposes Thousands of Websites to RCE Attacks HubSpot’s Jinjava Engine Vulnerability Exposes Thousands of Websites to RCE Attacks Cyber Security News
UEFI Shell Vulnerabilities Could Allow Hackers to Bypass Secure Boot on 200,000+ Laptops UEFI Shell Vulnerabilities Could Allow Hackers to Bypass Secure Boot on 200,000+ Laptops Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Log Monitoring Tools to Watch in 2026
  • Top Spam Filter Tools for 2026: A Comprehensive Guide
  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark