Fake Google Security site uses PWA app to steal credentials, MFA codes
ID: 7f92eefe-088c-55f2-a04f-8be97f1d12fc
STIX ID: report--7f92eefe-088c-55f2-a04f-8be97f1d12fc
Feed Name: Bleeping Computer
A phishing campaign leveraging a fake Google Security web page installs a malicious Progressive Web App (PWA) and an optional Android APK to harvest one‑time passcodes (via WebOTP), clipboard data, cryptocurrency addresses, contacts, and GPS location; the PWA also runs a service worker and WebSocket relay to proxy attacker traffic through victims' browsers and perform internal network scanning, while the APK requests extensive permissions (including device admin) to enable keystroke capture, notification interception, overlays, persistence, and full device data theft. Researchers (Malwarebytes) detail the attack flow, capabilities, persistence mechanisms, and remediation steps, and warn that the web app alone can perform significant data theft without the APK installed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
