Inside a fake Google security check that becomes a browser RAT
ID: 9a81b27f-31fb-5769-802a-088b3ec86b0c
STIX ID: report--9a81b27f-31fb-5769-802a-088b3ec86b0c
Feed Name: Malwarebytes Blog
A malicious site impersonating a Google Account security page (served from google-prism.com) lures users into installing a PWA that, via granted permissions and a service worker, harvests contacts, clipboard contents, GPS, intercepts OTPs, acts as an HTTP/WebSocket proxy to route attacker traffic through victims, performs local network scanning, queues exfiltrated data for later delivery, and can deliver an Android APK (com.device.sync, SHA-256: 1fe2be4582c4cbce8013c3506bc8b46f850c23937a564d17e5e170d6f60d8c08) which adds keystroke capture, accessibility monitoring, notification listening, autofill interception, device-admin persistence, and other high-risk capabilities; the report includes remediation steps and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
