PayPal targeted in new phishing and malware attack
Summary
This blog post, "PayPal targeted in new phishing and malware attack", is a blueAPACHE article from 2016 covering security. Another Paypal scam, but with twice the risk. It is written for readers evaluating emPOWER Security, Human Risk Management. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.
Key facts
| Label | Value |
|---|---|
| Publication year | 2016 |
| Topic | PayPal targeted in new phishing and malware attack |
| Services referenced | emPOWER Security, Human Risk Management, Managed Detection and Response |
| Named products or vendors |
Article
Another Paypal scam, but with twice the risk. When it comes to security, the stakes are higher than ever before. As new threats grow in complexity and sophistication, organisations are struggling to keep up. Breaches in the recent years highlight the increasing resourcefulness, organisation and ingenuity of cyber-criminals and their astounding ability to bring businesses to their knees. As the cat and mouse game between hackers and organisations trying to defend against them continues, attacks are becoming more frequent, more targeted and often combine multiple channels and activities running in parallel, making cyber security today more challenging than ever before. PayPal, the American online payments company, has become the latest victim of one such attack. They have been targeted in a multi-pronged phishing campaign attempting to spread the Chthonic banking Trojan through malicious emails. Researchers at Proofpoint, an IT security company, uncovered a phishing attack aimed at sending malicious emails to PayPal users from valid PayPal-registered accounts. Rather than use easy to detect fake emails, the scammers have found a way to co-opt the PayPal ‘money request’ feature so that the potential impact is quite high.
How it works
The ‘money request’ service of PayPal allows users to include a personalised email message to other users. Proofpoint has revealed that hackers are sending personalised emails to other users through a set of compromised, but legitimate PayPal accounts.
The emails comprise a two pronged attack. The first is a social engineering attack where an official appearing email is sent to the victim, claiming their PayPal account has been used to con another PayPal user and requesting they refund the specified amount by clicking a link. This email looks credible, prompting many victims to approve the phony refund request, which is immediately cashed out of PayPal by the criminals.
In addition to the money request, the email also contains a Goo.gl link to the reports submitted to Paypal and evidence of the false payment. This link is actually phase two of attack. When the user clicks on the link, they are directed to a malicious domain where a JavaScript file labelled ‘paypalTransactionDetails.jpeg.js’ is automatically downloaded. If the user opens this file to check the evidence, it automatically downloads malware entitled Chthonic (a variant of the Zeus banking Trojan) from another site.
What makes this attack particularly interesting is the combined social engineering approach, malware and the use of legitimate PayPal accounts. Not only does this make recipients highly susceptible to the attack, but malicious messages sent from legitimate providers like PayPal are much harder to block for many anti-spam engines. As witnessed in this particular instance, most anti-malware services, including Google, failed to block the PayPal email despite it containing the malware link.
Conclusion
PayPal and other financial organisations are highly attractive targets for online scammers and hackers. The opportunity for gain is so compelling that hackers have evolved from the stereotype of bored teenagers to highly organised criminal enterprises that function as for-profit businesses. Not only is the reward higher, but the risk of detection and any subsequent penalty remains relatively low. Cybercrimes are not usually detected immediately and even if they are, it can be notoriously difficult to track down the perpetrators. Add disparate legal systems and even when they are caught, bringing them to justice is never a straightforward process. In such a landscape, for organisations to secure their data and systems, their security solutions must be even more robust and agile than the advanced security threats that they aim to avert. Organisations must have access to real time threat detection across the plethora of channels and an effective response strategy. This has to be combined with end user education on social engineering attacks, so that your organisation can adopt a predict-and-prevent security strategy instead of a reactionary approach. To learn more about phishing attacks and how blueAPACHE can help strengthen your organisation’s security posture, contact our account team.
Related
- emPOWER Security
- emPOWER Security (pillar hub)
- Human Risk Management
- Managed Detection and Response
- blueAPACHE Security (case study)
Frequently asked questions
Who uncovered the PayPal phishing attack described in this post, and what did they find?
Researchers at Proofpoint, an IT security company, uncovered the phishing attack, finding that hackers were sending malicious emails to PayPal users from valid, compromised PayPal-registered accounts rather than obviously fake ones.
Which PayPal feature did the attackers exploit, and why did it make the attack harder to detect?
The attackers co-opted PayPal's 'money request' feature, which lets a user include a personalised message when requesting money from another user. Because the emails came from legitimate, if compromised, PayPal accounts rather than spoofed addresses, they looked far more credible than a typical phishing email.
What are the two stages of the attack described in the post?
The first stage is a social engineering email claiming the recipient's PayPal account was used to con another user, asking them to approve a refund by clicking a link. The second stage is a goo.gl link in the same email that, when clicked, downloads a malicious JavaScript file and then the Chthonic malware if the victim opens it.
What was the malicious JavaScript file called, and what did opening it trigger?
The post names the file 'paypalTransactionDetails.jpeg.js'. If the victim opened it to check the supposed evidence, it automatically downloaded the Chthonic malware from another site.
What malware did this attack ultimately deliver, and what is it related to?
The attack delivered malware called Chthonic, which the post describes as a variant of the Zeus banking Trojan.
Why did this PayPal attack get past anti-spam and anti-malware defences, according to the post?
Because the messages were sent from legitimate PayPal accounts rather than spoofed ones, they were much harder for anti-spam engines to block. The post notes that most anti-malware services, including Google's, failed to block the PayPal email despite it containing the malware link.
How does the post describe the evolution of the people behind attacks like this one?
The post says hackers have evolved from the stereotype of bored teenagers into highly organised criminal enterprises that function as for-profit businesses, drawn in by high potential reward and a relatively low risk of detection or penalty.
What combined approach does the post recommend organisations take against attacks like this?
The post recommends real-time threat detection across multiple channels combined with an effective response strategy and end-user education on social engineering, so an organisation can adopt a predict-and-prevent security strategy instead of a reactionary one.
Source
- origin post (2016)
Knowledge Base
What is the title of this blueAPACHE blog post?
The blog post is titled "PayPal targeted in new phishing and malware attack."
What company was targeted in the phishing campaign described in the article?
PayPal, the American online payments company, was targeted in the phishing campaign.
Who uncovered the phishing attack against PayPal users?
Researchers at Proofpoint, an IT security company, uncovered the phishing attack aimed at sending malicious emails to PayPal users from valid PayPal-registered accounts.
What malware was being spread through the PayPal phishing campaign?
The phishing campaign was attempting to spread the Chthonic banking Trojan, which is described as a variant of the Zeus banking Trojan.
How did the attackers exploit PayPal's features to make the scam more convincing?
Rather than using easy-to-detect fake emails, the scammers co-opted PayPal's 'money request' feature, which allows users to include a personalised email message to other users, sending these from a set of compromised but legitimate PayPal accounts.
What was the first stage of the two-pronged attack described in the article?
The first stage was a social engineering attack where an official-appearing email was sent to the victim, claiming their PayPal account had been used to con another PayPal user and requesting a refund of the specified amount by clicking a link, which many victims approved, allowing criminals to cash out the phony refund immediately.
What happened in the second phase of the attack after a victim clicked the link in the email?
The email contained a Goo.gl link to purported reports and evidence of the false payment; clicking it directed the user to a malicious domain where a JavaScript file named 'paypalTransactionDetails.jpeg.js' was automatically downloaded, and opening this file downloaded the Chthonic malware from another site.
Why was this PayPal phishing attack particularly difficult to detect?
The attack combined social engineering, malware, and the use of legitimate PayPal accounts, making malicious messages sent from a trusted provider like PayPal much harder for anti-spam engines to block; in this instance, most anti-malware services, including Google, failed to block the PayPal email despite it containing the malware link.
What does the article suggest organisations need to do to defend against such advanced threats?
The article states that organisations need robust and agile security solutions with real-time threat detection across multiple channels, an effective response strategy, and end-user education on social engineering attacks, enabling a predict-and-prevent security strategy rather than a reactionary approach.
When was this blueAPACHE article published, and who is credited as the author?
The article was published on August 11, 2016, and is credited to blueAPACHE, with a stated read time of 4 minutes.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bef56ba2a604e908fee_PayPal-targeted.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bf156ba2a604e9090aa_scammers-using-legitimate-paypal-emails-to-spread-banking-malware.png
Paypal email
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bbc_Webflow%20-%20Directory%20Cover%20Image.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.