Microsoft Visual Impersonation Wave

Target: Microsoft | Attack: ASCII Visual Deception | Active: 23 days | Trend: ? Increasing

Active Threat Campaign

Uses rn=m, 0=o character substitution to mimic microsoft.com. Targets Office 365 login credentials. Report suspicious activity to OziShield for free forensic analysis.

Latest variant: micr0soft.com (detected 3 weeks ago)

3
Total Detections
0.1
Avg Per Day
4
Countries
3
Known Variants
3
Peak (May 23)

Attack Pattern Breakdown

Distribution of deception techniques used in this campaign:

Visual Deception 100.0%

Geographic Intelligence

Detection distribution by location:

Australia 100.0%

Known Variants

Example domains detected in this campaign:

Recent Activity

Latest variants detected by OziShield:

micr0soft.com
Detected 3 weeks ago
micr0soft.com
Detected 3 weeks ago
micr0soft.com
Detected 3 weeks ago

How to Detect This Scam

Look for "rn" instead of "m", zero "0" instead of letter "o". Always check the address bar carefully.

What You Should Do

Do not enter credentials. Navigate directly to microsoft.com or office.com. Report to your IT team.

Report This Scam

If you've encountered this threat, report it to:

Scan Suspicious Links

Found a suspicious link? Check if it's part of this or another threat campaign.

Scan Link Free ?