logo

Hackers steal banking creds from iOS, Android users via PWA apps

ID: e5ee5f14-63df-5033-abf3-9e85db812ce4

STIX ID: report--e5ee5f14-63df-5033-abf3-9e85db812ce4

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-08-21

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Security researchers (ESET) documented active phishing campaigns that abuse progressive web applications (PWAs) and WebAPKs to impersonate banking apps and harvest credentials from Android and iOS users. Attackers use automated calls, SMS (smishing), and malicious social-media ads to lure victims to fake store pages or directly install PWAs; the campaigns target multiple banks in Europe and exfiltrate stolen data via distinct C2 infrastructures or Telegram, while evading native app-store installation warnings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.