Uses character substitution (rn=m, 0=o, l=i) to create fake PayPal domains. Targets payment credential theft. Report suspicious activity to OziShield for free forensic analysis.
Latest variant: paypa1.com (detected 3 weeks ago)
Distribution of deception techniques used in this campaign:
Detection distribution by location:
Example domains detected in this campaign:
Latest variants detected by OziShield:
Check for rn, vv, rri patterns in domain. Verify SSL certificate shows PayPal Inc. Look for character substitution: paypa1, paypaI, paypai.
Never click payment links in emails. Go directly to paypal.com. Enable 2FA. Report to phishing@paypal.com
If you've encountered this threat, report it to:
Found a suspicious link? Check if it's part of this or another threat campaign.
Scan Link Free ?