paypal1

New PayPal Phishing Abusing Microsoft365 Domains for Sophisticated Attacks

Share:

A new and sophisticated phishing scam has been uncovered, leveraging Microsoft 365 domains to trick users into compromising their PayPal accounts.

The attack exploits legitimate-looking sender addresses and URLs, making it harder for victims to recognize the phishing attempt.

Security experts, including Chief Information Security Officers (CISOs), have raised alarms about the growing menace, urging caution and vigilance, shared by Fortinet.

<img class=”i-amphtml-intrinsic-sizer” style=”box-sizing: border-box; margin: 0px; padding: 0px; border: 0px; outline: 0px; font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;” role=”presentation” src=”data:;base64,” alt=”” aria-hidden=”true” />
phishing mail

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

How the Scam Works

This phishing campaign uses Microsoft 365’s free trial domains to craft authentic-looking email addresses.

<img class=”i-amphtml-intrinsic-sizer” style=”box-sizing: border-box; margin: 0px; padding: 0px; border: 0px; outline: 0px; font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;” role=”presentation” src=”data:;base64,” alt=”” aria-hidden=”true” />
URL looks genuine

Once a scammer registers a trial domain, they set up deceptive distribution lists with obscure addresses resembling legitimate ones.

For example, an email might appear to originate from “Billingdepartments1[@]gkjyryfjy876.onmicrosoft.com,” which at first glance might look credible to unsuspecting users. Here’s the scam’s modus operandi step-by-step:

  1. The Money Request Email: The attacker uses the PayPal interface to send payment requests to the distribution list they created. This makes it appear PayPal itself is seeking money from the victims. The email is technically legitimate and passes sender authentication methods like SPF, DKIM, and DMARC checks, making it indistinguishable from real PayPal communications.
  2. The Phishing Hook: Upon receiving the email, victims who click the embedded link are directed to what looks like an official PayPal login page. The page displays the payment request, creating a sense of urgency and panic. Many victims proceed to log in without suspicion, thereby falling into the scammer’s trap.
  3. Account Takeover: Once the victim logs in, their PayPal account becomes linked to the scammer’s email address, such as “Billingdepartments1[@]gkjyryfjy876.onmicrosoft.com.” This allows the attacker to access the victim’s account, potentially transferring funds or stealing sensitive information.
<img class=”i-amphtml-intrinsic-sizer” style=”box-sizing: border-box; margin: 0px; padding: 0px; border: 0px; outline: 0px; font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;” role=”presentation” src=”data:;base64,” alt=”” aria-hidden=”true” />
PayPal login page showing a request for payment

Why This Scam is Dangerous

The cleverness of this attack lies in its leveraging of legitimate technologies. By using free Microsoft 365 test domains, the scammers bypass conventional detection systems.

<img class=”i-amphtml-intrinsic-sizer” style=”box-sizing: border-box; margin: 0px; padding: 0px; border: 0px; outline: 0px; font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;” role=”presentation” src=”data:;base64,” alt=”” aria-hidden=”true” />
scammer appears to have simply registered an MS365 test domain

The distribution list feature further obfuscates the true sender, creating plausible deniability. Even PayPal’s phishing detection instructions would fail to flag this method.

Most dangerously, the phishing email’s sender address and links appear authentic, and the email passes standard security checks. This raises the stakes, as even tech-savvy users might fall for the scam.

Experts urge vigilance when handling payment requests, even from seemingly legitimate sources. Here are some safety recommendations:

  • Verify Requests: Always double-check payment requests directly within your PayPal account rather than relying on email links.
  • Scrutinize Sender Addresses: Look carefully at the sender address for anomalies or inconsistencies.
  • Enable Two-Factor Authentication (2FA): This adds an extra layer of protection to your PayPal account.
<img class=”i-amphtml-intrinsic-sizer” style=”box-sizing: border-box; margin: 0px; padding: 0px; border: 0px; outline: 0px; font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;” role=”presentation” src=”data:;base64,” alt=”” aria-hidden=”true” />PayPal’s own phishing check instructions
PayPal’s phishing check instructions

As attackers continue to innovate, staying informed and cautious is vital. PayPal users, especially those handling corporate accounts, must prioritize cybersecurity to avoid falling victim to threats like these.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:19 am, Apr 20, 2025
weather icon 6°C
L: 5° | H: 7°
broken clouds
Humidity: 85 %
Pressure: 1008 mb
Wind: 7 mph NNE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:53 am
Sunset: 8:04 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
5° | 7°°C 0 mm 0% 10 mph 90 % 1008 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
8° | 16°°C 0.7 mm 70% 11 mph 94 % 1013 mb 0 mm/h
Tue Apr 22 10:00 pm
weather icon
7° | 15°°C 0.2 mm 20% 8 mph 83 % 1019 mb 0 mm/h
Wed Apr 23 10:00 pm
weather icon
9° | 14°°C 1 mm 100% 15 mph 96 % 1018 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
9° | 12°°C 0 mm 0% 8 mph 86 % 1025 mb 0 mm/h
Today 7:00 am
weather icon
6° | 7°°C 0 mm 0% 8 mph 84 % 1008 mb 0 mm/h
Today 10:00 am
weather icon
11° | 13°°C 0 mm 0% 10 mph 69 % 1007 mb 0 mm/h
Today 1:00 pm
weather icon
19° | 19°°C 0 mm 0% 10 mph 58 % 1007 mb 0 mm/h
Today 4:00 pm
weather icon
14° | 14°°C 0 mm 0% 7 mph 73 % 1007 mb 0 mm/h
Today 7:00 pm
weather icon
14° | 14°°C 0 mm 0% 6 mph 78 % 1007 mb 0 mm/h
Today 10:00 pm
weather icon
9° | 9°°C 0 mm 0% 4 mph 90 % 1007 mb 0 mm/h
Tomorrow 1:00 am
weather icon
8° | 8°°C 0 mm 0% 3 mph 92 % 1007 mb 0 mm/h
Tomorrow 4:00 am
weather icon
8° | 8°°C 0 mm 0% 1 mph 94 % 1007 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€74,918.15
0.41%
Ethereum(ETH)
€1,419.73
1.33%
Tether(USDT)
€0.88
0.01%
XRP(XRP)
€1.83
0.13%
Solana(SOL)
€124.11
2.41%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.139092
-0.41%
Shiba Inu(SHIB)
€0.000011
0.49%
Pepe(PEPE)
€0.000007
2.40%
Scroll to Top