• CERTIFICATE
    • Eminent VARs of India
    • Best OEM 2023
  • SYNDICATION
    • AMD
    • DELL TECHNOLOGIES
    • HITACHI
    • LOGMEIN
    • MICROSOFT
    • RIVERBED
    • STORAGECRAFT
    • THALES
  • EVENTS
  • GO DIGITAL
  • INFOGRAPHICS
  • PRESS
    • Press Release PR News Wire
    • Press Release Business Wire
    • GlobeNewsWire
  • SPECIAL
    • WHITE PAPER
    • TECHNOMANIA
    • SME
    • SMART CITY
    • SERVICES
    • EDITOR SPEAK
    • CSR INITIATIVES
    • CHANNEL GURU
    • CHANNEL CHIEF
    • CASE STUDY
  • TECHTREND
    • VAR PANCHAYAT
    • TELECOM
    • SOFTWARE
    • POWER
    • PERIPHERALS
    • NETWORKING
    • LTE
    • CHANNEL BUZZ
    • ASK AN EXPERT
  • SUBSCRIBE
  • Apps
  • Gaming
  • KDS
  • Security
  • Telecom
  • WFH
  • Subscriber to Newsletter
  • April Issue
  • Blogs
  • Vlogs
  • Faceoff AI
    

HOME
NEWS

Avanan Report: PhishPal: How PayPal Became a Hackers’ Haven


By VARINDIA - 2023-02-24
Avanan Report: PhishPal: How PayPal Became a Hackers’ Haven

By Jeremy Fuchs, Cybersecurity Researcher/Analyst at Avanan, A Check Point Software Company

 

Introduction

In July of last year, we wrote about a new campaign where hackers are sending phishing emails and malicious invoices directly from PayPal.

This is different from the plenty of attacks we’ve seen that spoof PayPal. This is a malicious invoice that comes directly from PayPal.

And since it comes directly from PayPal, it becomes incredibly difficult not only for email security services to stop but also for end-users to respond to it accordingly.

In this attack brief, researchers at Avanan, a Check Point Software Company, will discuss how threat actors are taking advantage of PayPal to send malicious invoices directly to users.

Attack

In this attack, hackers are sending malicious invoices directly from PayPal;

* Vector: Email

* Type: Malware

* Techniques: Social Engineering, Impersonation, Malicious Invoice

* Target: Any end-user

 

Email Example #1

This email comes directly from PayPal–notice that the sender address is service@paypal.com.

The body of the email, however, could alert some eagle-eyed users that something is amiss. For one, the grammar and spelling is all over the place. The phone number they list is not related to PayPal. However, it offers another way for hackers to get your information and money. For one, if you call that number, now they have your cell phone number and can use it for more attacks. And it’s another chance to scam you on the phone.

Email # 2

This is a slight variation, whereby the hackers claim that a Norton Antivirus 360 subscription has been renewed. They want to call and cancel, by calling the listed number, which is not associated with PayPal or Norton.

 

Techniques

Google ‘PayPal scam’ and the results are pretty jarring. You’ll find very similar attacks to the ones listed above. We’ve written a number of them, as have many others. There are lists related to all the different email scams from PayPal.

Why have these proliferated? There are a few reasons.

For one, anyone can create a PayPal account. It’s free and takes a few seconds. It’s very easy to create an invoice. It’s two clicks.

PayPal offers you the ability to send 20 of these at a time. They even offer tools to create more professional-looking invoices.

That ease of use is appealing to hackers. Beyond that, the email comes directly from PayPal. The email itself is not malicious–there are countless legitimate invoices sent via PayPal every day. An email coming from service@paypal.com will pass all SPF, DKIM, DMARC checks. And it will likely pass many other checks. It likely won’t be the first time interacting with the sender. The URL will be clean.

These are things that traditional email security solutions look for, as well as next-gen solutions. Sussing out that this email will require the use of advanced AI and ML that’s trained on an incredibly large database to figure out that this attack is indeed an attack.

If the email service can’t figure it out, there are other issues for the user to figure out. For one, the sender’s email address is gone. It’s just a nickname. It’ll say, “A small reminder from billing desk.” It won’t say, “billing.desk@company.com.” It just says Billing Desk. So the user can’t look to see if there are discrepancies in the sender address.

That makes it incredibly easy for the hacker to impersonate a family member or a boss.

In short, this is an attack that’s incredibly easy to do and incredibly hard to stop.

Best Practices: Guidance and Recommendations

To guard against these attacks, security professionals can do the following:

* Before calling an unfamiliar service, Google the number and check your accounts to see if there were, in fact, any charges

* Implement advanced security that looks at more than one indicator to determine in an email is clean or not

* Encourage users to ask IT if they are unsure about the legitimacy of an email

See What’s Next in Tech With the Fast Forward Newsletter

SECURITY
View All
Zscaler announces AI innovations to its Data Protection Platform
Technology

Zscaler announces AI innovations to its Data Protection Platform

by VARINDIA 2024-05-20
SHIELD to enhance Swiggy’s fraud prevention and detection capabilities
Technology

SHIELD to enhance Swiggy’s fraud prevention and detection capabilities

by VARINDIA 2024-05-20
Axis Communications announces its first thermometric camera designed for Zone/Division 2
Technology

Axis Communications announces its first thermometric camera designed for Zone/Division 2

by VARINDIA 2024-05-20
SOFTWARE
View All
Hitachi Vantara and Veeam announce Global Strategic Alliance
Technology

Hitachi Vantara and Veeam announce Global Strategic Alliance

by VARINDIA 2024-05-16
Adobe launches Acrobat AI Assistant for the Enterprise
Technology

Adobe launches Acrobat AI Assistant for the Enterprise

by VARINDIA 2024-05-11
Oracle Database 23ai offers the power of AI to Enterprise Data and Applications
Technology

Oracle Database 23ai offers the power of AI to Enterprise Data and Applications

by VARINDIA 2024-05-10
START - UP
View All
Data Subject Access Request is an integrated module within ID-REDACT®
Technology

Data Subject Access Request is an integrated module within ID-REDACT®

by VARINDIA 2024-04-30
SiMa.ai Secures $70M Funds from Maverick Capital
Technology

SiMa.ai Secures $70M Funds from Maverick Capital

by VARINDIA 2024-04-05
Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure
Technology

Sarvam AI collaborates with Microsoft to bring its Indic voice LLM to Azure

by VARINDIA 2024-02-08

Tweets From @varindiamag

Nothing to see here - yet

When they Tweet, their Tweets will show up here.

CIO - SPEAK
Automation has the potential to greatly improve efficiency and production

Automation has the potential to greatly improve efficiency and production

by VARINDIA
Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

Various approaches are followed to enhance efficiency, productivity, and cost-effectiveness

by VARINDIA
Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

Technology can be leveraged in several ways to boost efficiency, productivity and reduce cost

by VARINDIA
Start-Up and Unicorn Ecosystem
GoDaddy harnesses AI power for new domain name recommendations

GoDaddy harnesses AI power for new domain name recommendations

by VARINDIA
UAE’s du Telecom selects STL as a strategic fibre partner

UAE’s du Telecom selects STL as a strategic fibre partner

by VARINDIA
JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

JLR and Dassault Systèmes extend partnership for All Vehicle Programs worldwide

by VARINDIA
Rapyder partners with AWS to accelerate Generative AI led innovation

Rapyder partners with AWS to accelerate Generative AI led innovation

by VARINDIA
ManageEngine integrates its SIEM solution with Constella Intelligence

ManageEngine integrates its SIEM solution with Constella Intelligence

by VARINDIA
Elastic replaces traditional SIEM game with AI-driven security analytics

Elastic replaces traditional SIEM game with AI-driven security analytics

by VARINDIA
Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

Infosys and ServiceNow to transform customer experiences with generative AI-powered solutions

by VARINDIA
Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

Crayon Software Experts India inaugurates its ISV Incubation Center in Kolkata

by VARINDIA
Dassault Systèmes to accelerate EV charging infrastructure development in India

Dassault Systèmes to accelerate EV charging infrastructure development in India

by VARINDIA
Tech Mahindra and Atento to deliver GenAI powered business transformation services

Tech Mahindra and Atento to deliver GenAI powered business transformation services

by VARINDIA
×

Reproduction in whole or in part in any form or medium without express written permission of Kalinga Digital Media Pvt. Ltd. is prohibited.

  • Distributors & VADs
  • Industry Associations
  • Telco's in India
  • Indian Global Leaders
  • Edit Calendar
  • About Us
  • Advertise Us
  • Contact Us
  • Disclaimer
  • Privacy Statement
  • Sitemap

Copyright varindia.com @1999-2024 - All rights reserved.