A sophisticated phishing campaign exploits a subtle typographical trick, replacing 'm' with 'rn' to divert users' attention to Microsoft, tricking victims into revealing sensitive login details. Attackers are using the domain “rnicrosoft.com” to impersonate the well-known technology company.
See also: As Windows turns 40, Microsoft faces backlash over artificial intelligence

By replacing the letter 'm' with the combination 'rn', the scammers create a visual "duplicate" that is almost impossible to distinguish from the legitimate domain at a quick glance. This technique, known as typosquatting, relies heavily on the font rendering used in modern email clients and browsers.
When letters are placed close to each other, the centering between the 'r' and 'n' often mimics the structure of the letter 'm', tricking the brain into automatically "correcting" the mistake.
Harley Sugarman, CEO of Anagram, recently highlighted this particular attack method, noting that the emails often mimic the official Microsoft logo, layout, and tone of legitimate communications.
The effectiveness of this type of attack relies on its subtlety. On high-resolution computer screens, the difference can be noticed by a careful observer, but the brain’s tendency to “predict” text often masks the anomaly. The threat is even greater on mobile devices, where screen space is limited and the address bar often truncates the full URL. Attackers exploit this situation by registering domains that look like legitimate ones to facilitate phishing, vendor invoice scams, and campaigns impersonating internal HR personnel.
See also: Microsoft: Azure Firewall integration with Security Copilot

When the user is convinced that the email comes from a trusted source, they are more likely to click on malicious links or download infected files.
Replacing the letter 'm' with 'rn' is just one of many variations used by attackers. Other common tactics include replacing the letter 'o' with a zero or adding hyphens to well-known brand names to create the illusion of authenticity.
Defending against these homoglyph and typosquatting requires a change in user behavior, not just reliance on automated filters. Security experts recommend that users fully verify the sender address before interacting with any spam email.
Hovering over links to reveal the actual URL, or holding down on the link on mobile devices, can reveal the scam before any connection is made. Additionally, analyzing email headers, especially the “Reply-To”, can show whether the scammer is forwarding replies to an external, unverified account.
In cases where unexpected password reset requests are received, the safest course of action is to ignore the email link completely and access the official service directly through a new browser tab.
See also: Microsoft: Azure network “hit” by 15 Tbps DDoS attack

Organizations are advised to train staff in these recognition scenarios to avoid the automatic and instinctive movement of clicking on notifications that look familiar.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
