PULSE NAME
Hackers Use rn Typo Trick to Impersonate Microsoft and Marriott in New Phishing Attack
WHITE PetrP.73 2026-01-25 Modified: 2026-01-25
5
IOCs
LOW VOLUME
A recent phishing campaign has emerged that employs a sophisticated technique known as "homoglyph" attacks, targeting customers of both Marriott International and Microsoft. Attackers are utilizing a typographical trick that replaces the letter "m" with the combination of "rn" (the characters r and n), creating fraudulent domains that closely mimic the legitimate websites of these well-known brands. In the case of Marriott International, a security firm named Netcraft has reported the discovery of several malicious domains specifically designed to impersonate the hotel chain. These fake websites aim to deceive users into revealing their loyalty account credentials or other sensitive personal information related to hotel bookings and guest data. The close resemblance to legitimate domains raises the risk of unsuspecting customers falling victim to these phishing efforts.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (5)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain micros0ft.com 2026-01-25
domain microsoft-support.com 2026-01-25
domain rnarriotthotels.com 2026-01-25
domain rnarriottinternational.com 2026-01-25
domain rnicrosoft.com 2026-01-25