PWA phishing on Android and iOS – Week in security with Tony Anscombe

Cyber Security

Video

Phishing using PWAs? ESET Research’s latest discovery might just ruin some users’ assumptions about their preferred platform’s security

ESET researchers have recently revealed an uncommon type of phishing campaign using Progressive Web Apps (PWAs) that targeted the clients of a prominent Czech bank. 

The technique used installed a phishing application from a third-party website without the user having to allow third-party app installation. This is because PWAs are simply websites bundled into what feels like a standalone app, enhanced by the usage of native system prompts.

For iOS users, such an action might break their assumptions about their platform’s security. On Android, this could result in the silent installation of a special kind of APK, which even appears to be installed from the Google Play store. 

Learn more in Tony’s latest video.

Connect with us on FacebookTwitterLinkedIn and Instagram.

Products You May Like

Articles You May Like

Mirai Variant Murdoc Botnet Exploits AVTECH IP Cameras and Huawei Routers
TikTok Goes Dark in the U.S. as Federal Ban Takes Effect January 19, 2025
Critical Flaws in WGS-804HPT Switches Enable RCE and Network Exploitation
Lazarus Group Targets Developers in New Data Theft Campaign
Trump Terminates DHS Advisory Committee Memberships, Disrupting Cybersecurity Review

Leave a Reply

Your email address will not be published. Required fields are marked *