Tech »  Topic »  This new phishing campaign uses a fake Google Account security page to steal passcodes and more

This new phishing campaign uses a fake Google Account security page to steal passcodes and more


(Image credit: Shutterstock)
  • Attackers are abusing Progressive Web Apps (PWAs) on Android
  • Victims lured via phishing site google-prism[dot]com into installing malicious PWA
  • PWA harvests clipboard, crypto wallets, OTPs, GPS, and more

Threat actors have begun turning to Progressive Web Apps (PWA) to do their evil bidding on Android, stealing login credentials, cryptocurrency wallet data, GPS information, and more, experts have warned.

Security researchers from Malwarebytes recently detailed one such campaign they spotted in the wild, starting with a phishing email, luring people to a fake Google site google-prism[dot]com.

Under the pretense of enhanced security, the victims are walked through a four-step “security” check that includes installing a malicious PWA.

Yet another phishing campaign impersonates trusted Google services - here's what we knowWatch out - that Google Tasks email could be a scam, and land you in hot water at workHackers observed injecting legitimate banking apps ...
Copyright of this story solely belongs to techradar.com . To see the full text click HERE