Hackers Use Fake PayPal Notices to Steal Credentials, Deploy RMMs
ID: 1bdcb40a-d8f3-59bb-99b3-16ba0973b066
STIX ID: report--1bdcb40a-d8f3-59bb-99b3-16ba0973b066
Feed Name: Infosecurity Magazine (News)
CyberProof documented a wave of phishing-led intrusions that employ high-urgency PayPal-themed lures and phone-based social engineering to get victims to install legitimate RMM tools (LogMeIn Rescue then AnyDesk), allowing attackers to achieve persistence (scheduled tasks, disguised startup shortcuts) and evade EDR alerts; the advisory warns these RMM backdoors can lead to full corporate compromise or ransomware and recommends tightening phishing controls, restricting RMM ports, protecting remote services, maintaining offline backups, and reinforcing user training as part of a zero-trust approach.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
