Threat actors have been abusing PayPal’s legitimate invoicing and alert mechanisms to deliver phishing lures that bypass common email security controls and create urgency around supposed unauthorized transactions. By creating fraudulent PayPal business accounts and sending requests via PayPal’s own Money Request/Invoice workflow, the resulting messages can pass authentication checks and even display the BIMI “blue tick” indicator in some inboxes, increasing victim trust; the malicious content is placed in fields like Note to Customer and typically includes a fake support phone number to initiate a callback scam.
In a related PayPal-themed campaign, victims who call the provided number are socially engineered into installing legitimate remote monitoring and management (RMM) tools so attackers can access systems and steal credentials. Reporting indicates operators initially used LogMeIn Rescue and later shifted to AnyDesk, a redundancy that can help sustain operations when tooling is blocked or detected; analysts warned that RMM-enabled access can be monetized beyond immediate fraud, including resale for broader enterprise compromise and potential ransomware deployment. Recommended mitigations include restricting outbound access to common RMM ports/tools where feasible, strengthening user verification procedures for payment-related emails (verify directly in PayPal rather than via email content), and reviewing third-party/RMM tool risk and monitoring for unauthorized installs.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Socket's Threat Research Team identified five malicious Chrome extensions masquerading as productivity tools for platforms including Workday, NetSuite, and SAP SuccessFactors. The extensions, which had more than 2,300 users, were designed to steal authentication cookies and tokens, hijack sessions, inject cookies to bypass MFA, and obstruct access to security settings and audit pages.
In the PayPal-themed phishing campaign, attackers used phone-based social engineering to persuade victims to install legitimate remote monitoring and management tools, enabling credential theft and remote access. CyberProof reported the operators initially used LogMeIn Rescue and later switched to AnyDesk to preserve access if one tool was blocked or detected.
Attackers began abusing PayPal's legitimate invoice and money request features to send scam emails claiming unauthorized charges and urging recipients to call fraudulent support numbers. Because the messages are sent through PayPal, they can pass authentication checks and may display trusted branding indicators such as a BIMI verification mark.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.