We found this fake-invoice campaign while scammers were still building it
ID: 5a5594f4-b7d2-5b65-a672-b1074f730385
STIX ID: report--5a5594f4-b7d2-5b65-a672-b1074f730385
Feed Name: Malwarebytes Blog
A live 'phantom invoice' refund scam campaign is being staged that sends convincing fake receipts impersonating brands (PayPal, Amazon, Geek Squad) to coerce victims into calling attacker-controlled phone numbers; the phone call is used to obtain remote access, payment details, or fraudulent 'refund' payments. The report includes detected template placeholders showing the campaign was intercepted during rollout, and it lists malicious domains and callback numbers as indicators, plus guidance for spotting and responding to these scams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
