Phishing, Identity

Fraudulent PayPal alerts tapped for credential compromise

PayPal settles for $2 million with New York State DFS over 2022 breach of customer accounts. (Adobe Stock)

Infosecurity Magazine reports that threat actors have leveraged fraudulent PayPal alerts to deploy legitimate remote monitoring and management tools in a bid to pilfer credentials as part of a phishing attack campaign.

Intrusions commenced with the delivery of fake PayPal email alerts meant to create a sense of urgency, followed by phone-based social engineering that lured targets into downloading RMM software, with attackers initially launching LogMeIn Rescue before switching to AnyDesk, according to an analysis from Cyberproof. Such redundancy in RMM utilization, which was observed in an earlier Broadcom report, facilitates more clandestine phishing operations.

"While the immediate motivation behind this campaign appears financial, the long-term risk is significant. Access gained through these RMM 'backdoors' can be sold to Advanced Persistent Threat (APT) actors, leading to full corporate compromise or ransomware deployment," said CyberProof, which recommended the implementation of network access restrictions to typical RMM ports, up-to-date software, offline backups, and third-party RMM tool risk assessments to mitigate potential compromise.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds