logo

Hackers Use ‘rn’ Typo Trick to Impersonate Microsoft and Marriott in New Phishing Attack

ID: e768523f-63c9-549a-bda9-89475b25d8e9

STIX ID: report--e768523f-63c9-549a-bda9-89475b25d8e9

Feed Name: cybersecurityNews.com

Threat Score
60/100

Date Published: 2026-01-25

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Executive Summary:** A homoglyph (typosquatting) phishing campaign is impersonating Marriott and Microsoft by registering domains that replace the letter "m" with "rn" (e.g., `rnarriottinternational.com`, `rnicrosoft.com`) to trick users—especially on mobile—into divulging credentials or personal data; the report lists multiple malicious domains flagged by security firms and recommends blocking those IOCs, verifying sender addresses, hovering over links, manually navigating to official sites, and using password managers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.