“Users are first deceived via the Google ad that looks entirely legitimate and then again via a lookalike domain,” Jérôme Segura, head of threat intelligence at security provider Malwarebytes,
Back in 2017, Google Chrome 59 supposedly fixed the Punycode phishing attack. E.g. story: https://www.engadget.com/2017-04-17-google-chrome-phishing-u...
Maybe a dedicated criminal studied the Chromium source code that checks Punycode and noticed a flaw where it would allow 'ķ' in place of 'k' ???
https://www.xn--80ak6aa92e.com/ --> fake "аррӏе.com" triggers phishing warning
https://xn--eepass-vbb.info/ --> fake "ķeepass.info" does not trigger warning