A new PayPal phishing kit targets compromised WordPress sites stealing identity details and government documents.
A recently discovered phishing kit targets PayPal users and attempts to steal a large set of personal information from victims, including government ID documents and photos.
Over 400 million people and businesses use PayPal as an online payment solution.
The kit is hosted on legitimate WordPress that have been compromised, which allows it to evade detection to some extent.
Researchers at internet technology company Akamai found the phishing kit after the operator placed it on their WordPress.
The threat actor targets poorly secured websites and performs a brute force using a list of common credential found online. They use this access to install a file management plugin that allows the phishing kit to be uploaded to the compromised website.

To Akamai discovered that a method used by the phishing kit to evade detection is the cross‑referencing of IP addresses in domains belonging to a specific set of companies, including some organisations in the cyber‑security sector.
See also: PayPal: Allows crypto transfers to external wallets

The researchers observed that the author of the phishing kit made an effort to make the fake page look professional and mimic PayPal's original location as much as possible.
One aspect they noticed was that the author uses htaccess to rewrite the URL so that it doesn't end with the PHP. This adds to a cleaner, more polished look that lends legitimacy.
Also, all UI elements in the forms are styled according to PayPal's theme, so that phishing pages have a seemingly authentic appearance.
The theft of a victim's personal data begins with the presentation of a CAPTCHA, a step that creates a false sense of legitimacy.

After this stage, the victim is prompted to log into their PayPal account using the email address and password, which are automatically delivered to the threat actor.
That is not all, though. Under the pretext of «unusual activity» that is related to the victim's account, the threat actor requests additional verification information.
On the next page, the victim is asked to provide a series of personal and financial details that include payment card data along with the card verification code, the physical address, the social security number, the mother's maiden name.
It appears that the PayPal phishing kit was built to obtain all the victim's personal information. In addition to the card data typically collected in phishing scams, it also requires the social security number, the mother's maiden name, and even the card PIN for ATM transactions.
Collecting so much information is not typical for phishing kits. However, this goes even further and asks victims to link their email account with PayPal. This would give the intruder a token that could be used to access the contents of the provided email address.

Despite having collected a massive amount of personal information, the threat actor is not finished. In the next step, they ask the victim to upload their official identity documents to verify their identity.
Acceptable documents are a passport, national ID card , or driver's license , and the upload process comes with specific instructions, just like PayPal or a legitimate service would ask of their users.
Cybercriminals could use all this information for a variety of illegal activities, ranging from anything related to identity theft to money laundering (e.g. creating crypto, registering companies) and maintaining anonymity when purchasing services to taking over bank accounts or cloning payment cards.
See also: PayPal lays off employees to reduce costs
Uploading government documents and taking a selfie to verify them is a bigger risk for a victim than simply losing credit card information — it could be used to create crypto trading accounts in the victim’s name. These could then be used for money laundering, tax evasion, or providing anonymity for other cybercrimes.

Even though the PayPal phishing kit appears sophisticated, researchers discovered that the file upload capability is accompanied by a vulnerability that could be exploited to upload a web shell and take control of the compromised website.
Given the sheer volume of information requested, the scam may seem obvious to some users. However, Akamai believe that this particular element of social engineering is what makes the kit successful.
They explain that identity verification is normal these days and it can be done in many ways. «People judge brands and companies for their security measures these days», say the researchers.
The use of a captcha challenge signals from the outset that additional verification may be expected. Using the same methods as legitimate services, the threat factor establishes the victim's trust.
Users are advised to check the domain name of a page that requests sensitive information. They can also go to the official service page, typing it manually into the browser, to verify whether the authentication is correct.
Source: bleepingcomputer.com
