By Guru Baran
Publication Date: 2025-11-24 10:38:00
A sophisticated phishing campaign is currently leveraging a subtle typographical trick to bypass user vigilance, deceiving victims into handing over sensitive login credentials. Attackers utilize the domain “rnicrosoft.com” to impersonate the tech giant.
By replacing the letter ‘m’ with the combination of ‘r’ and ‘n’, fraudsters create a visual doppleganger that is nearly indistinguishable from the legitimate domain at a casual glance.
This technique, known as typosquatting, relies heavily on the font rendering used in modern email clients and web browsers.
When placed closely together, the kerning between ‘r’ and ‘n’ often mimics the structure of the letter ‘m’, fooling the brain into autocorrecting the error.
Harley Sugarman, CEO of Anagram, recently highlighted this specific vector, noting that the emails often mirror the official logo, layout, and tone of legitimate Microsoft correspondence.



