Paypal users are being lured into clicking on a malicious link embedded in a tweet that appears to come from the financial transaction service, according to a report from Proofpoint.
Messages are arriving from two different fraudulent social media customer service accounts in a phishing attack technique dubbed angler phishing, based on the predation characteristic of the anglerfish, which uses a fleshy protuberance on its head to lure in prey.
“In an angler phishing attack, a fake customer-support account promises to help customers, but instead attempts to steal credentials,” Proofpoint explained.
The strategy has been used since at least early 2016 targeting several industries, but the majority have focused on customer support accounts for financial services brands, Proofpoint reported.
In this latest campaign, researchers at Proofpoint detected an angler phish attack targeting PayPal users from two fake PayPal Twitter accounts. The tweet encourages recipients to click over to the actual PayPal Twitter account, @PayPal, for assistance in an urgent matter. However, the fraudsters are monitoring the replies on the official PayPal Twitter page in order to sweep up replies to exploit for their attacks.
In addition, when victims receive a reply from the phony PayPal Twitter accounts, they’re fooled again as the reply has the PayPal logo emboldened as an account image, and the handle seems official, except it amends the word “Ask” at the beginning of the handle.
Targets are lured into entering their PayPal credentials into the seemingly legitimate, but fake page. The bad actors are thus provided with the personal information they need to gain access to accounts and transfer out funds held there.
Proofpoint reported that PayPal is aware of this scam and is working with Twitter to resolve it.
