New phishing toolkit uses PWAs to steal login credentials
ID: 83d1eeaf-0dfe-5856-b37a-06c9ff04d2c5
STIX ID: report--83d1eeaf-0dfe-5856-b37a-06c9ff04d2c5
Feed Name: Bleeping Computer
Security researcher mr.d0x released PWA-based phishing templates that let attackers and red teamers create desktop-like apps with hidden browser chrome and a fake address bar to convincingly mimic corporate login portals and steal credentials. The kit can be delivered via fake software sites prompting PWA installation; once installed, Windows may encourage taskbar pinning and the app reopens its start_url, increasing victim engagement. Chrome may periodically reveal the real domain, but user habit of checking URLs may be undermined, and there are no broad group policies to block PWA installation across enterprises. The templates are available on GitHub, and the technique is expected to see adoption despite requiring user consent to install.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
