logo

Be careful what you pwish for – Phishing in PWA applications

ID: 4473f3c9-9fd1-53fc-aaaa-08f7620d8606

STIX ID: report--4473f3c9-9fd1-53fc-aaaa-08f7620d8606

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2024-08-20

Date Updated: 2026-05-01

...
...

ESET researchers describe an active, cross-platform phishing campaign that uses Progressive Web Apps (PWAs) and WebAPKs to install convincing fake banking apps on iOS and Android without triggering typical third‑party install warnings; victims are socially engineered via malvertising, SMS and automated calls, and credentials are exfiltrated to Telegram bots or C2 panels. The report includes detailed technical analysis, timeline, IoCs (files, domains, IPs), MITRE ATT&CK mappings, and evidence of two distinct operator groups responsible for campaigns primarily targeting Czech banks and isolated cases in Hungary and Georgia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.