Stop, Look and Think

by Kerry LeBlanc

Recently we sent out an IT Security Flash describing a type of attack for which we all need to be on the lookout. This attack takes advantage of the fact that on a computer certain letters can be replaced with look-a-likes. Think back to when you were copying something from a paper document: is that a 0 (zero) or an O (capital letter ‘o’)? An l (lowercase “L”) or a 1 (one). Characters that have different meanings but look alike are known as homoglyphs. With certain fonts they will look very different as they do here.

The issue arises when it is used as an email address or in the body of an email. If not looking closely, then it is an easy matter to slip it by the unwary recipient. This attack is known as the internationalized domain name (IDN) homograph attack. It  is a way a malicious party may deceive computer users about what remote system they are communicating with, by exploiting the fact that many different characters look alike (i.e., they are homographs, hence the term for the attack, although technically homoglyph is the more accurate term for different characters that look alike).

This kind of spoofing attack is also known as script spoofing. Modern computers incorporate numerous writing systems, and, for a number of reasons, similar-looking characters such as Greek Ο, Latin O, and Cyrillic О were not coded the same.

Take a look at the email addresses below, can you spot the difference? Maybe, what about on your phone?

  • security @bloventus.com
  • security @bioventus.com
  • security @bioventus.com
  • security @biioness.com
  • security @boness.com
  • security @bioness.com

Here are some examples with websites.

  • www.bioventus.com – www.bloventus.com
  • www.bioness.com – www.bloness.com
  • www.bioriess.com – www.bioness.com

This style of attack is not new, but with the changes recently within Bioventus and Bioness, there is more and more chance of this type of attack being used against us. The bad guys are relying on this period of change to help them deceive us. It is important to take that extra time stop, look and think for a second or two before you click on any link in an email or open an attachment during this time of integration.

Remember to look carefully, if something does not feel right about the email go with your instinct. Make sure it is an email that you were expecting or one that you can verify with the sender. Especially with emails requesting changes to payment or banking details. If there is any doubt, verify it. You can contact the sender or forward it to your security team to look into. Use the resources provided and together we will keep Bioventus safe and moving forward!