paypal1

New PayPal Phishing Abusing Microsoft365 Domains for Sophisticated Attacks

Teilen:

A new and sophisticated phishing scam has been uncovered, leveraging Microsoft 365 domains to trick users into compromising their PayPal accounts.

The attack exploits legitimate-looking sender addresses and URLs, making it harder for victims to recognize the phishing attempt.

Security experts, including Chief Information Security Officers (CISOs), have raised alarms about the growing menace, urging caution and vigilance, shared by Fortinet.

<img class="”i-amphtml-intrinsic-sizer”" style="”box-sizing:" border-box; margin: 0px; padding: border: outline: font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;” role ="”presentation”" src ="”data:;base64,”" alt ="””" aria-hidden="”true”" />
phishing mail

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

How the Scam Works

This phishing campaign uses Microsoft 365’s free trial domains to craft authentic-looking email addresses.

<img class="”i-amphtml-intrinsic-sizer”" style="”box-sizing:" border-box; margin: 0px; padding: border: outline: font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;” role ="”presentation”" src ="”data:;base64,”" alt ="””" aria-hidden="”true”" />
URL looks genuine

Once a scammer registers a trial domain, they set up deceptive distribution lists with obscure addresses resembling legitimate ones.

For example, an email might appear to originate from “Billingdepartments1[@]gkjyryfjy876.onmicrosoft.com,” which at first glance might look credible to unsuspecting users. Here’s the scam’s modus operandi step-by-step:

  1. The Money Request Email: The attacker uses the PayPal interface to send payment requests to the distribution list they created. This makes it appear PayPal itself is seeking money from the victims. The email is technically legitimate and passes sender authentication methods like SPF, DKIM, and DMARC checks, making it indistinguishable from real PayPal communications.
  2. The Phishing Hook: Upon receiving the email, victims who click the embedded link are directed to what looks like an official PayPal login page. The page displays the payment request, creating a sense of urgency and panic. Many victims proceed to log in without suspicion, thereby falling into the scammer’s trap.
  3. Account Takeover: Once the victim logs in, their PayPal account becomes linked to the scammer’s email address, such as “Billingdepartments1[@]gkjyryfjy876.onmicrosoft.com.” This allows the attacker to access the victim’s account, potentially transferring funds or stealing sensitive information.
<img class="”i-amphtml-intrinsic-sizer”" style="”box-sizing:" border-box; margin: 0px; padding: border: outline: font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;” role ="”presentation”" src ="”data:;base64,”" alt ="””" aria-hidden="”true”" />
PayPal login page showing a request for payment

Why This Scam is Dangerous

The cleverness of this attack lies in its leveraging of legitimate technologies. By using free Microsoft 365 test domains, the scammers bypass conventional detection systems.

<img class="”i-amphtml-intrinsic-sizer”" style="”box-sizing:" border-box; margin: 0px; padding: border: outline: font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;” role ="”presentation”" src ="”data:;base64,”" alt ="””" aria-hidden="”true”" />
scammer appears to have simply registered an MS365 test domain

The distribution list feature further obfuscates the true sender, creating plausible deniability. Even PayPal’s phishing detection instructions would fail to flag this method.

Most dangerously, the phishing email’s sender address and links appear authentic, and the email passes standard security checks. This raises the stakes, as even tech-savvy users might fall for the scam.

Experts urge vigilance when handling payment requests, even from seemingly legitimate sources. Here are some safety recommendations:

  • Verify Requests: Always double-check payment requests directly within your PayPal account rather than relying on email links.
  • Scrutinize Sender Addresses: Look carefully at the sender address for anomalies or inconsistencies.
  • Enable Two-Factor Authentication (2FA): This adds an extra layer of protection to your PayPal account.
<img class="”i-amphtml-intrinsic-sizer”" style="”box-sizing:" border-box; margin: 0px; padding: border: outline: font-size: 18px; vertical-align: baseline; background: transparent; max-width: 100%; display: block !important;” role ="”presentation”" src ="”data:;base64,”" alt ="””" aria-hidden="”true”" />PayPal’s own phishing check instructions
PayPal’s phishing check instructions

As attackers continue to innovate, staying informed and cautious is vital. PayPal users, especially those handling corporate accounts, must prioritize cybersecurity to avoid falling victim to threats like these.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:20 am, Mai 19, 2025
Wetter-Symbol 10°C
L: 9° | H: 11°
overcast clouds
Luftfeuchtigkeit: 85 %
Druck: 1020 mb
Wind: 5 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:02 am
Sonnenuntergang: 8:51 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
9° | 11°°C 0 mm 0% 11 mph 85 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 21°°C 0 mm 0% 9 mph 69 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
14° | 22°°C 0 mm 0% 12 mph 63 % 1020 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 12 mph 64 % 1023 mb 0 mm/h
Fr. Mai 23 10:00 pm
Wetter-Symbol
7° | 19°°C 0 mm 0% 9 mph 69 % 1024 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 6 mph 85 % 1021 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
12° | 15°°C 0 mm 0% 7 mph 76 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
16° | 19°°C 0 mm 0% 9 mph 54 % 1020 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 11 mph 40 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 9 mph 46 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 63 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 5 mph 66 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 5 mph 69 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,035.71
-0.37%
Ethereum(ETH)
€2,119.05
-4.66%
Fesseln(USDT)
€0.89
-0.01%
XRP(XRP)
€2.09
-1.34%
Solana(SOL)
€146.21
-2.90%
USDC(USDC)
€0.89
0.01%
Dogecoin(DOGE)
€0.194470
0.22%
Shiba Inu(SHIB)
€0.000013
-1.23%
Pepe(PEPE)
€0.000012
3.27%
Peanut das Eichhörnchen(PNUT)
€0.281946
1.59%
Nach oben scrollen