Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Developer confirms Crimson Desert will have no post-launch microtransactions

    Cheap gaming handheld: Mangmi Pocket Max with AMOLED reviewed

    MagicX reveals color options for its two new handhelds

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026

      To avoid accusations of AI cheating, college students are turning to AI

      January 29, 2026

      ChatGPT can embrace authoritarian ideas after just one prompt, researchers say

      January 24, 2026
    • Business

      The HDD brand that brought you the 1.8-inch, 2.5-inch, and 3.5-inch hard drives is now back with a $19 pocket-sized personal cloud for your smartphones

      February 12, 2026

      New VoidLink malware framework targets Linux cloud servers

      January 14, 2026

      Nvidia Rubin’s rack-scale encryption signals a turning point for enterprise AI security

      January 13, 2026

      How KPMG is redefining the future of SAP consulting on a global scale

      January 10, 2026

      Top 10 cloud computing stories of 2025

      December 22, 2025
    • Crypto

      Metaplanet Reports FY2025 Results as Bitcoin Unrealized Losses Top $1 Billion

      February 17, 2026

      Crypto’s AI Pivot: Hype, Infrastructure, and a Two-Year Countdown

      February 17, 2026

      The RWA War: Stablecoins, Speed, and Control

      February 17, 2026

      Jeffrey Epstein Emails Show Plans to Meet Gary Gensler To Talk Crypto

      February 17, 2026

      Bitcoin Bounce Fades, Q1 Losses Deepen, and New Price Risk Back in Focus

      February 17, 2026
    • Technology

      Developer confirms Crimson Desert will have no post-launch microtransactions

      February 17, 2026

      Cheap gaming handheld: Mangmi Pocket Max with AMOLED reviewed

      February 17, 2026

      MagicX reveals color options for its two new handhelds

      February 17, 2026

      New Casio G-Shock metal bezel watches with red display coming to more countries

      February 17, 2026

      MSI’s $5,090 RTX 5090 Lightning Z cracks from thermal shock during 2,500W BIOS test

      February 17, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Booking.com phishing campaign uses sneaky ‘ん’ character to trick you
    Technology

    Booking.com phishing campaign uses sneaky ‘ん’ character to trick you

    TechAiVerseBy TechAiVerseAugust 14, 2025No Comments4 Mins Read2 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Booking.com phishing campaign uses sneaky ‘ん’ character to trick you
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Booking.com phishing campaign uses sneaky ‘ん’ character to trick you

    Threat actors are leveraging a Unicode character to make phishing links appear like legitimate Booking.com links in a new campaign distributing malware.

    The attack makes use of the Japanese hiragana character, ん, which can, on some systems, appear as a forward slash and make a phishing URL appear realistic to a person at a casual glance.

    BleepingComputer has further come across an Intuit phishing campaign using a lookalike domain using the letter L instead of ‘i’ in Intuit.

    Booking.com phishing links using Japanese homoglyphs

    The attack, first spotted by security researcher JAMESWT, abuses the Japanese hiragana character “ん” (Unicode U+3093), which closely resembles the Latin letter sequence ‘/n’ or ‘/~’, at a quick glance in some fonts. This visual similarity enables scammers to create URLs that appear to belong to the genuine Booking.com domain, but direct users to a malicious site.

    Below is a copy of the phishing email shared by the security researcher:

    Copy of phishing email shared by security researcher JamesWT

    The text in the email, https://admin.booking.com/hotel/hoteladmin/… itself is deceptive. While it may look like a Booking.com address, the hyperlink points to:

    https://account.booking.comんdetailんrestric-access.www-account-booking.com/en/

    Phishing page as it appears in a web browser

    When rendered in a web browser’s address bar, the ‘ん’ characters can trick users into thinking they are navigating through a subdirectory of booking.com.

    In reality, the actual registered domain is www-account-booking[.]com, a malicious lookalike, and everything before that is just a deceptive subdomain string.

    Victims who click through are eventually redirected to:

    www-account-booking[.]com/c.php?a=0

    This in turn delivers a malicious MSI installer from a CDN link, https://updatessoftware.b-cdn[.]net/john/pr/04.08/IYTDTGTF.msi

    Samples of the malicious site are available on abuse.ch’s MalwareBazaar, with any.run analysis showing the infection chain. The MSI file is used to drop further payloads, potentially including infostealers or remote access trojans.

    This phishing tactic exploits homoglyphs. A homoglyph is a character that looks similar to another character but belongs to a different character set or alphabet. These visually similar characters can be exploited in phishing attacks or to create misleading content. For example, Cyrillic character “О” (U+041E) may appear identical to the Latin letter “O” (U+004F) to a human, but they are different characters.

    Given their visual similarities, homoglyphs have been leveraged time and time again by threat actors in homograph attacks and phishing emails. Defenders and software developers have also, over the last few years, rolled out security measures that make it easy for users to distinguish between distinct homoglyphs.

    This isn’t the first time threat actors have targeted Booking.com customers either.

    In March this year, Microsoft warned of phishing campaigns impersonating Booking.com and using ClickFix social engineering attacks to infect hospitality workers with malware.

    In 2023, Akamai revealed how hackers were redirecting hotel guests to fake Booking.com sites to steal credit card information.

    ‘Lntuit’ not Intuit

    BleepingComputer’s Sergiu Gatlan spotted a separate phishing campaign involving users being targeted with Intuit-themed emails.

    These emails appear to come from and take you to intuit.com addresses, but instead use domains starting with Lntuit—which, in lowercase, can resemble “intuit” in certain fonts. A simple yet effective technique.

    Intuit phishing email from ‘Lntuit.com’ viewed on Mailspring for macOS (Sergiu Gatlan)

    The unusually narrow layout of this email in desktop clients suggests it was primarily designed for mobile viewing, with attackers banking on mobile users clicking the “Verify my email” phishing link without closely inspecting it.

    The button takes users to: https://intfdsl[.]us/sa5h17/

    How Intuit phishing email appears on mobile (Sergiu Gatlan)

    Interestingly, the illicit link, when accessed directly i.e. not from the target user’s email account appears to redirect the user back to the legitimate Intuit.com login page at https://accounts.intuit.com/app/sign-in.

    These incidents are a reminder that attackers will continue to find creative ways to abuse typography for social engineering.

    To protect yourself, always hover over links before clicking to reveal the true target.

    Users should always check the actual domain at the rightmost end of the address before the first single / — this is the real registered domain. Granted, the use of visually deceptive Unicode characters like ‘ん’ create additional hurdles, and demonstrates that visual URL inspection alone isn’t foolproof.

    Keeping endpoint security software up to date adds another layer of defense against attacks since modern phishing kits often deliver malware directly, after a phishing link is clicked.


    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleHow A Giant Parachute Helps The B-52 Come To A Complete Stop
    Next Article Microsoft fixes Windows Server bug causing cluster, VM issues
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Developer confirms Crimson Desert will have no post-launch microtransactions

    February 17, 2026

    Cheap gaming handheld: Mangmi Pocket Max with AMOLED reviewed

    February 17, 2026

    MagicX reveals color options for its two new handhelds

    February 17, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025682 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025265 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025155 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025114 Views
    Don't Miss
    Technology February 17, 2026

    Developer confirms Crimson Desert will have no post-launch microtransactions

    Developer confirms Crimson Desert will have no post-launch microtransactions – NotebookCheck.net News ⓘ steamCrimson Desert’s…

    Cheap gaming handheld: Mangmi Pocket Max with AMOLED reviewed

    MagicX reveals color options for its two new handhelds

    New Casio G-Shock metal bezel watches with red display coming to more countries

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Developer confirms Crimson Desert will have no post-launch microtransactions

    February 17, 20262 Views

    Cheap gaming handheld: Mangmi Pocket Max with AMOLED reviewed

    February 17, 20262 Views

    MagicX reveals color options for its two new handhelds

    February 17, 20262 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    This new Roomba finally solves the big problem I have with robot vacuums

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.