Be careful what you pwish for – Phishing in PWA applications
ID: 4473f3c9-9fd1-53fc-aaaa-08f7620d8606
STIX ID: report--4473f3c9-9fd1-53fc-aaaa-08f7620d8606
Feed Name: WeLiveSecurity (ESET Research)
ESET researchers describe an active, cross-platform phishing campaign that uses Progressive Web Apps (PWAs) and WebAPKs to install convincing fake banking apps on iOS and Android without triggering typical third‑party install warnings; victims are socially engineered via malvertising, SMS and automated calls, and credentials are exfiltrated to Telegram bots or C2 panels. The report includes detailed technical analysis, timeline, IoCs (files, domains, IPs), MITRE ATT&CK mappings, and evidence of two distinct operator groups responsible for campaigns primarily targeting Czech banks and isolated cases in Hungary and Georgia.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
