HomeSecurityNew phishing campaign abuses PayPal

New phishing campaign abuses PayPal

A new phishing campaign is abusing PayPal address settings to send fake purchase notifications and tricking users into granting remote access to scammers.

PayPal phishing

Last month, users and organizations received emails from PayPal saying: “You have added a new address. This is just a quick confirmation that you have added an address to your PayPal account.”

The phishing email included the new address that was allegedly added to the PayPal account, and there was also a message referring to a purchase confirmation for a MacBook M4. If this purchase had not been made by the users, they should report it to the company by calling a number that was also included in the email.

“Confirmation: The shipping address for the MacBook M4 Max 1TB ($1098.95) has changed. If you did not authorize this update, please contact PayPal at +1-888-668-2508,” the message states.

See also: Darcula phishing service will allow creation of DIY phishing kits

The emails are sent directly from PayPal from the address “service@paypal.com,” leading people to worry that their accounts have been compromised. However, those who received this message confirmed that no new addresses were actually added to their accounts. In some cases, the email was sent to people who didn’t even have a PayPal account, indicating that it was a scam.

However, since the emails are legitimate PayPal emails, they bypass security and spam filters. How did the scammers manage to send these phishing emails?

The emails are designed to make recipients believe their account has been compromised to purchase a MacBook. They want to scare the recipient of the email into calling a phone number that supposedly belongs to PayPal's support department.

If the victim calls, they will hear a pre-recorded message stating that they have contacted PayPal customer service and that they must wait until a person is available in the support department. Then, the call will attempt to connect the victim with an alleged employee.

The scammer tries to convince the victim that their account has been compromised and will ask them to download and run a piece of software so that they can “help” them regain access to the account and block the alleged transaction.

The scammer directs the victim to a website such as pplassist[.]com and asks for a service code (provided by the fake PayPal employee). Entering this code will download a ConnectWise ScreenConnect client [VirusTotal] from lokermy.numaduliton[.]icu or other websites, which the victim is asked to run.

See also: Phishing attack hides JavaScript using Unicode

Typically, in these scams, the scammer gains computer the victim's and attempts to run malware, steal data from the computer, or steal money from bank accounts.

Anyone who receives a legitimate email from PayPal stating that the address on the account has been updated and contains a false purchase confirmation should ignore the message and not call the embedded phone number.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Instead, it is preferable that they log into their PayPal account and verify that no new addresses have been added.

New phishing campaign abuses PayPal

How the PayPal scam works

When BleepingComputer first received the email from service@paypal.com, there was some confusion, as the email was sent to an email address that does not have a PayPal account associated with it.

The mail headers showed that the emails were legitimate and passed the email security checks DKIM. It was not clear at first how these legitimate messages were being sent from PayPal until BleepingComputer observed this text at the bottom of the email.

See also: Phishing: Russian hackers exploit Signal's “Linked Devices” feature

“If you want to link your credit card to this address or make it your primary address, log in to your PayPal account and go to your Profile. Since this address is a gift address, you can send packages with just one click.“.

Further investigation revealed that “gift addresses” are simply additional addresses that you can profile your PayPal. In a test, BleepingComputer added a new address to one of its accounts and pasted the scammer’s fake MacBook purchase confirmation message into the Address 2 field.

After saving the address, PayPal sent the same confirmation email, notifying of the new address added, which also included the fake purchase message.

Thus, they apparently managed to create the fake message.

After further analysis of the mail headers, it was discovered that the email was actually sent to “noreply_@usaea.institute”, which is the email address associated with the scammer’s PayPal address.

The headers further show that this email address automatically forwards the email it receives to “bill_complete1@zodu.onmicrosoft.com”, an account associated with a Microsoft 365 tenant.

This account is probably a mailing list that automatically forwards any email it receives to all other members of the group. In this case, the members are the scammer's targets.

When they add the scam address to PayPal, the payment platform will send an email confirmation to the threat actor's email, who will then forward it to the Microsoft 365 account, which will then forward it to all targets on the mailing list.

See also: New Device Code Phishing Attack Steals Authentication Tokens

New phishing campaign abuses PayPal

Protection

Users should be wary of messages they receive from strangers or from supposedly well-known companies. Many times, phishing attacks start with a simple message asking for the user's login details.

Next, they should regularly update their software, including the operating system and applications. These updates often include security that can protect the user from the latest threats.

Using reliable security software, such as an antivirus or security app, can help protect against attacks. These tools can identify and block suspicious websites or messages that are trying to steal user information.

Finally, users should be careful when downloading applications from the internet. Many times, applications that seem innocent may contain hidden code that can steal user information or cause other security threats.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS