{"id":6840,"date":"2025-01-08T10:07:08","date_gmt":"2025-01-08T16:07:08","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/unconventional-cyberattacks-take-over-paypal-accounts"},"modified":"2025-01-08T10:07:08","modified_gmt":"2025-01-08T16:07:08","slug":"unconventional-cyberattacks-aim-to-take-over-paypal-accounts","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/01\/08\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts\/","title":{"rendered":"Unconventional Cyberattacks Aim to Take Over PayPal Accounts"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt87652e3742bb0cad\/677e5800b679550b4487aa4e\/paypal_Robert_Wilkinson_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An unconventional <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/phishwp-plugin-hijacks-wordpress-e-commerce-checkouts\">phishing campaign<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> convincingly impersonates <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/paypal-breach-exposed-pii-of-nearly-35k-accounts\">online payments service <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">PayPal to try to trick users into logging in to their accounts to make a payment; in reality, the login allows attackers to take over an account. The novel part of the attack is the abuse of a legitimate feature within Microsoft 365 to create a test domain, which then allows the attackers to create an email distribution list that makes the payment-request messages appear to be legitimately sent from PayPal.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Carl Windsor, CISO for Fortinet Labs, discovered the campaign when he himself was targeted by it, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/phish-free-paypal-phishing\">he revealed<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in a blog post published today.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Windsor received a request in his inbox from a sender with a nonspoofed PayPal email address seeking a payment of $2,185.96. The person requesting the money was someone called Brian Oistad, and aside from the &#8220;to&#8221; address not being Windsor&#8217;s email address \u2014 &nbsp;it was addressed to Billingdepartments1[@]gkjyryfjy876.onmicrosoft.com \u2014 &nbsp;there were few obvious signs it was not a genuine email, he said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;What&#8217;s interesting about this attack is that it doesn\u2019t use traditional phishing methods,&#8221; Windsor wrote. &#8220;The email, the URLs, and everything else are perfectly valid.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That validity might persuade an average email user to click on the link in the email, which redirects them to a PayPal login page showing a request for payment.<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" data-discover=\"true\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/phishwp-plugin-hijacks-wordpress-e-commerce-checkouts\" target=\"_self\">PhishWP Plug-in Hijacks WordPress E-Commerce Checkouts<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">At this point, &#8220;some folks might be tempted to log in with their account details, however, this would be extremely dangerous,&#8221; he wrote. That&#8217;s because the login page links the target&#8217;s PayPal account address with the address it was sent to \u2014 Billingdepartments1[@]gkjyryfjy876.onmicrosoft.com, controlled by the attacker \u2014 not their own email address.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Abusing Microsoft 365 Test Domains for Cybercrime\">Abusing Microsoft 365 Test Domains for Cybercrime<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The campaign works because the scammer appears to have registered a Microsoft 365 test domain \u2014 which is free for three months \u2014 and then created a distribution list containing target emails. This allows any messages sent from the domain to bypass standard email security checks, Windsor explained in the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Then, &#8220;on the PayPal Web portal, they simply request the money and add the distribution list as the address,&#8221; he wrote.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This money request is then distributed to the targeted victims, and the Microsoft 365 Sender Rewrite Scheme (SRS) rewrites the sender to, for example, &#8220;bounces+SRS=onDJv=S6[@]5ln7g7.onmicrosoft.com, which will <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/novel-smtp-smuggling-technique-slips-past-dmarc-email-protections\">pass the SPF\/DKIM\/DMARC check,<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8221; Windsor added.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Once the panicking victim logs in to see what is going on, the scammer\u2019s account (Billingdepartments1[@]gkjyryfjy876.onmicrosoft.com) gets linked to the victim\u2019s account,&#8221; he wrote. &#8220;The scammer can then take control of the victim&#8217;s PayPal account \u2014 a neat trick \u2026 [that] would sneak past even PayPal\u2019s own phishing check instructions.&#8221;<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" data-discover=\"true\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/thousands-of-buggy-beyondtrust-systems-still-exposed\" target=\"_self\">Thousands of BeyondTrust Systems Remain Exposed<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Indeed, abusing a vendor feature to deliver <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/fishxproxy-phishing-kit-cybercriminals-success\">the phishing message<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> does give the attackers a stealthy advantage when it comes to bypassing typical email security, a security expert notes.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;The emails are sent from a verified source and follow an identical template to legitimate messages, such as a standard PayPal payment request,&#8221; says Elad Luz, head of research at Oasis Security, a provider of non-human identity management. &#8220;This makes them difficult for mailbox providers to distinguish from genuine communications.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Cyber Defense: Create a &quot;Human Firewall&quot; Against Phishing\">Cyber Defense: Create a &#8220;Human Firewall&#8221; Against Phishing<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Because the attack appears to be a genuine email, the best solution to avoid falling prey to it is what Windsor calls the &#8220;human firewall,&#8221; or &#8220;someone who has been trained to be aware and cautious of any unsolicited email, regardless of how genuine it may look,&#8221; he wrote in the post.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This, of course, highlights the need to ensure your workforce is receiving <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/in-cybersecurity-mitigating-human-risk-goes-far-beyond-training\">the training<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> they need to spot threats like this to keep themselves \u2014 and your organization \u2014 safe,&#8221; Windsor noted.<\/span><\/p>\n<p data-component=\"related-article\" class=\"RelatedArticle\"><span data-testid=\"related-article-title\" class=\"RelatedArticle-Title\">Related:<\/span><a class=\"RelatedArticle-RelatedContent\" data-discover=\"true\" href=\"https:\/\/www.darkreading.com\/threat-intelligence\/recorded-future-russias-undesirable-designation-compliment\" target=\"_self\">Recorded Future: Russia&#8217;s &#8216;Undesirable&#8217; Designation Is a Compliment<\/a><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It is also possible to create a rule within email security scanners to &#8220;look for multiple conditions that indicate that this email is being sent via a distribution list,&#8221; to help detect a campaign that uses this vector, he added.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Another potential mitigation is to use artificial intelligence (AI)-based security tools that use neural networks to analyze social graph patterns, among other techniques, &#8220;to help spot these hidden interactions by analyzing user behaviors more deeply than static filters,&#8221; Stephen Kowski, field chief technology officer (CTO) at SlashNext Email Security+, tells Dark Reading.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;That kind of proactive detection engine recognizes unusual group messaging patterns or requests that slip through basic checks,&#8221; he says. &#8220;A thorough inspection of user interaction metadata will catch even this sneaky approach.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/unconventional-cyberattacks-take-over-paypal-accounts\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An unconventional phishing campaign convincingly impersonates online payments service PayPal<\/p>\n","protected":false},"author":12,"featured_media":6841,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6840","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?fit=4884%2C2747&ssl=1",4884,2747,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/01\/unconventional-cyberattacks-aim-to-take-over-paypal-accounts.png?fit=4884%2C2747&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6840"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6840\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6841"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}