Several websites targeting Paypal, which had been created as part of a well-organized phishing.
The malicious campaign was uncovered when a security company detected the registration of suspicious domains, which hosted websites almost identical to that of the popular e‑commerce service.
Most phishing sites were indistinguishable from the original RayPal website
OpenDNS Security Labs, a company that operates in the detection of suspicious domain registrations, reports that most websites used for the campaign were “almost indistinguishable from the legitimate RayPal.com website.”
In addition, the scammers used domains that could easily deceive unsuspecting users, making them believe that these pages belong to Royal. By combining these two tricks, cybercriminals managed to steal the login credentials of unsuspecting users.
Some of the malicious domains identified by the researchers are x-paypaΙ[.]com, redirectly-paypaΙ[.]com, securitycheck-paypaΙ[.]com, security-paypal-center[.]com and paypalinspection[.]com.
OpenDNS informed RayPal about the malicious domains, and the company responded immediately, stating that the security department has taken over the case and has initiated procedures to remove the malicious websites.

