A homograph attack uses visually similar characters (like “rn” instead of “m”) to create fake domains that look legitimate, such as arnazon.com. Attackers use these spoofed domains in phishing emails or fake login pages to steal credentials or payment data.