PayPal Phishing
ID: d78c1bd3-332b-5374-8938-e59a7bf46668
STIX ID: report--d78c1bd3-332b-5374-8938-e59a7bf46668
Feed Name: WatchGuard Secplicity Blog
This report analyzes a PayPal-branded phishing campaign that used a URL shortener and newly-registered attacker domains (examples: phonedisney.com, meansfat.com, service-account.genuinelysmash.com) to collect login credentials, full PII (name, address, phone, SSN, mother’s maiden name) and validated credit-card details; the phish employed session-bound keys to prevent repeated analysis and ultimately redirected victims to the real PayPal site, and the author notes DNSWatch blocks these domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
