logo

New PayPal Phishing Abusing Microsoft365 Domains for Sophisticated Attacks

ID: ec9cd908-2f40-5134-9660-2aa93172fc40

STIX ID: report--ec9cd908-2f40-5134-9660-2aa93172fc40

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2025-01-09

Date Updated: 2026-04-22

Author: Divya

...
...

A phishing campaign has been observed in which attackers register Microsoft 365 trial domains and create deceptive distribution lists to send legitimate-looking PayPal payment requests that pass email authentication (SPF/DKIM/DMARC). Recipients who click the links are taken to convincing PayPal login pages, allowing attackers to link and take over accounts; the report highlights the tactic's ability to bypass standard detection and recommends verifying payment requests directly in PayPal and enabling 2FA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.