PayPal Users Targeted in Sophisticated Phishing Attack
A recently observed phishing campaign is targeting PayPal users with fake pages that are well designed and difficult to distinguish from the real ones, ESET researchers warn.
The attack was observed only a couple of weeks after Gmail users were targeted in a phishing campaign that used legitimate-looking URLs capable of tricking even tech-savvy people. The attackers were even able to bypass two-factor authentication protection by accessing the compromised email accounts immediately.
The attack against PayPal users, ESET reveals, uses a very convincing bait as well, with fake websites and email messages meant to trick users into revealing their login credentials and other personal information.
The phishing emails include logos and wording that seems legitimate, yet users paying attention can immediately spot grammar and syntax errors that suggest the author isn’t a native English speaker, which is a clue that something is not right.
The email urges the user to log into their account and includes what looks like a “Log In” button, which in fact takes the victims to a landing page that presents them with a fake login screen. Because it uses an SSL certificate, the page attempts to fool users into believing it is authentic.
The domain, however, has nothing to do with PayPal sites, and are clearly scam URLs. After the user enters their information, another message with fake information is presented to them, asking for more personal details. Thus, the security researchers suggest that the attackers aren’t looking only for the victims’ money, but also after their identities.
To give a sense of urgency, the page claims that the user won’t be able to access the PayPal account until the requested information is provided. The page, however, contains more clues that something isn’t right, as it even asks for the user’s Social Security Number, which applies to US citizens only, but also asks which country the victim is from.
“If you’re concerned about PayPal security, you should log directly into PayPal.com itself and update your security settings, and if you know someone who has fallen victim, the first step should be to change their PayPal password before more damage occurs,” ESET notes.
Source | securityweek