PhishPal: How PayPal Became a Hackers’ Haven
Introduction In July of last year, Check Point Software wrote about a new campaign where hackers are sending phishing emails and malicious invoices directly from PayPal . This is different from the plenty of attacks we’ve seen that spoof PayPal. This is a malicious invoice that comes directly from PayPal. And since it comes directly from PayPal, it becomes incredibly difficult not only for email security services to stop but also for end-users to respond to it accordingly. In this attack brief, researchers at Avanan, a Check Point Software Company, will discuss how threat actors are taking advantage of PayPal to send malicious invoices directly to users. Attack In this attack, hackers are sending malicious invoices directly from PayPal; Vector: Email Type: Malware Techniques: Social Engineering, Impersonation, Malicious Invoice Target: Any end-user Email Example #1 This e...