3 ms·
I agree, this is most likely a case of someone using the same email and password on multiple sites (like the 100 million account leak from LinkedIn)
by devopsproject 10y ago
I agree, this is most likely a case of someone using the same email and password on multiple sites (like the 100 million account leak from LinkedIn)
- ryanlol 10y agoProbably not, that type of compromise tends to be common in targeted attacks. Not as much in generic fraud like this, as just the credentials wouldn't have been enough to easily automatically identify this guy as a good target. He probably had some bot on his computer that recorded him using paypal and what not, and because paypal has some seriously impressive fraud detection mechanisms the attacker opted to take over teamviewer (if teamviewer is at all involved here, could be VNC provided by the malware for all we know) on his computer. Now, judging by the way these things generally work the guy running the bots and the guy running remote desktop on his computer are hardly ever the same person.