The PayPal Invoice That Passed Every Check Because PayPal Actually Sent It
ID: 988e69de-30a7-5684-8c87-7a542ee4ee2b
STIX ID: report--988e69de-30a7-5684-8c87-7a542ee4ee2b
Feed Name: IRONSCALES
A PayPal invoice-cancellation phishing campaign used legitimately authenticated PayPal-sent emails (SPF/DKIM/DMARC passed) with all links pointing to PayPal pages, while the Reply-To header directed responses to a merchant domain controlled by the attacker; behavioral detection (IRONSCALES/Themis) flagged it and community validation confirmed phishing. The report provides IOCs ([email protected], [email protected], kissimmeenotarypublic.com, 173.0.84.6, d=paypal.com s=pp-dkim1) and recommends verifying Reply-To headers before replying to invoices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
