Hackers steal banking creds from iOS, Android users via PWA apps

Hackers steal banking creds from iOS, Android users via PWA apps

Threat actors started to use progressive web applications to impersonate banking apps and steal credentials from Android and iOS users.

Progressive web apps (PWA) are cross-platform applications that can be installed directly from the browser and offer a native-like experience through features like push notifications, access to device hardware, and background data syncing.

Using this type of apps in phishing campaigns allows evading detection, bypass app installation restrictions, and gain access to risky permissions on the device without having to serve the user a standard prompt that could raise suspicion.

The technique was first observed in the wild in July 2023 in Poland, while a subsequent campaign that launched in November of the same year targeted Czech users.

Cybersecurity company ESET reports that it is currently tracking two distinct campaigns relying on this technique, one targeting the Hungarian financial institution OTP Bank and the other targeting TBC Bank in Georgia.

However, the two campaigns appear to be operated by different threat actors. One uses a distinct command and control (C2) infrastructure to receive stolen credentials, while the other group logs stolen data via Telegram.

Infection chain

ESET says that the campaigns rely on a broad range of methods to reach their target audience, including automated calls, SMS messages (smishing), and well-crafted malvertising on Facebook ad campaigns.

In the first two cases, the cybercriminals trick the user with a fake message about their banking app being outdated and the need to install the latest version for security reasons, providing a URL to download the phishing PWA.

PWA campaigns infection flow
PWA campaigns infection flow
Source: ESET

In the case of malicious advertisements on social media, the threat actors use the impersonated bank’s official mascot to induce a sense of legitimacy and promote limited-time offers like monetary rewards for installing a supposedly critical app update.

One of the malicious ads used in the phishing campaign
One of the malicious ads used in the phishing campaign
Source: ESET

Depending on the device (verified via the User-Agent HTTP header), clicking on the ad takes the victim to a bogus Google Play or App Store page.

Fake Google Play portal
Fake Google Play installation prompt (left) and progress (right)
Source: ESET

Clicking on the ‘Install’ button prompts the user to install a malicious PWA posing as a banking app. In some cases on Android, the malicious app is installed in the form of a WebAPK – a native APK generated by Chrome browser.

The phishing app uses the official banking app’s identifiers (e.g. logo legitimate-looking login screen) and even declares Google Play Store as the software source of the app.

The malicious WebAPK on the victim's homescreen and the phishing login page
The malicious WebAPK (left) and the phishing login page (right)
Source: ESET

The appeal of using PWAs on mobile

PWAs are designed to work across multiple platforms, so attackers can target a broader audience through a single phishing campaign and payload.

The key benefit, though, lies in bypassing Google’s and Apple’s installation restrictions for apps outside the official app stores, as well as “install from unknown sources” warning prompts that could alert victims to potential risks.

PWAs can closely mimic the look and feel of native apps, especially in the case of WebAPKs, where the browser logo on the icon and the browser interface within the app are hidden, so distinguishing it from legitimate applications is nearly impossible.

PWA (left) and legitimate app (right). WebAPKs are indistinguishable
PWA (left) and legitimate app (right). WebAPKs are indistinguishable as they lose the Chrome logo from the icon.
Source: ESET

These web apps can get access to various device systems through browser APIs, such as geolocation, camera, and microphone, without requesting them from the mobile OS’s permissions screen.

Ultimately, PWAs can be updated or modified by the attacker without user interaction, allowing the phishing campaign to be dynamically adjusted for greater success.

Abuse of PWAs for phishing is a dangerous emerging trend that could gain new proportions as more cybercriminals realize the potential and benefits.

A few months back, we reported about new phishing kits targeting Windows accounts using PWAs. The kits were created by security researcher mr.d0x specifically to demonstrate how these apps could be used to steal credentials by creating convincing corporate login forms.

BleepingComputer has contacted both Google and Apple to ask if they plan to implement any defenses against PWAs/WebAPKs, and we will update this post with their responses once we hear back.

Source link

Visited 1 times, 1 visit(s) today

Related Article

Uefa unveils Champions best XI with 2️⃣ Brazilians, have your say 🗣

This Sunday (1), UEFA announced the best player of the competition this season, as well as the “team” of the main club tournament in Europe. And, first of all, it is worth remembering that, in “normal” years, that is, those that are not World Cup years, the highlights of the Champions League usually “do well”

Although more than 99.95% of Earth's gold is locked in the molten core, tiny amounts may be coming up to the surface in magma, a study found. A lava fountain at Kilauea in Hawaii is seen in early May.

Gold is escaping from Earth’s core, revealing its ‘leaks,’ scientists say

Editor’s note: A version of this story appeared in CNN’s Wonder Theory science newsletter. To get it in your inbox, sign up for free here. CNN  —  For a long time, there has been a missing puzzle piece in Jerusalem’s history. Though ancient texts offered some clues, an archaeological record of the city during the

"I watched helplessly as water washed my family away"

I watched helplessly as water washed my family away

Azeezat Olaoluwa BBC News, Mokwa Town Gift Ufuoma Adamu Yusuf lost his wife and newborn baby in the floods which swept through his town Adamu Yusuf’s life has been upended since he lost nine of his family members in Tiffin Maza, one of two communities in his town worst-hit by floods in north-central Nigeria. The

Ginny & Georgia Season 3 Episode 1-10 Release Date, Time, Where to Watch

Ginny & Georgia Season 3 Episode 1-10 release date and time is not too far away, and fans want to know what the television series has in store for the upcoming installment. The comedy drama follows how a young teenager, alongside her free-spirited mother, moves to a new town seeking a fresh start. However, beneath

Doué’s sensational Champions League performance for PSG launches him into a new dimension

PARIS (AP) — Translate Désiré Doué’s name into English and you get the words “coveted” and “gifted.” Both seem highly appropriate, considering how the 19-year-old’s stunning performance for Paris Saint-Germain in Saturday’s Champions League final launched him into soccer’s stratosphere, making Doué a player every team would love to have. Advertisement Doué scored with two

Patricia Krenwinkel in 2020

‘Manson Family’ member who smeared blood on walls recommended for parole

A former follower of cult leader Charles Manson, who is serving a life sentence for her role in a 1969 Los Angeles killing spree, has been recommended for parole. Patricia Krenwinkel, 77, the longest-serving female inmate in California, is one of two remaining so-called “Manson Family” members still in prison. In 1971, she was convicted

New liaison office chief in first public appearance with Hong Kong community visit

New liaison office chief in first public appearance with Hong Kong community visit

The director of Beijing’s liaison office in Hong Kong made his first visit to the community on Sunday, two days after he took up the role, saying his appointment came with heavy responsibilities but reflected the trust Chinese President Xi Jinping placed in him. Zhou Ji, the executive deputy director of the Hong Kong and

Weekly Forex Forecast - June 01th

Weekly Forex Forecast – June 01th

I wrote on 25th May that the best trades for the week would be: Long of Bitcoin following a daily (New York) close above $111,743. This did not set up. Long of the GBP/USD currency pair. This gave a loss of 0.54%. Short of the USD/ZAR currency pair. This gave a loss of 1.01%. The

Why There’s No New The Handmaid’s Tale Season 6 Episode This Week

The tenth episode of The Handmaid’s Tale Season 6 recently dropped. It showcased June reflecting on her experiences in Gilead. Subsequently, fans grew curious about the future of the series. So, is there a new The Handmaid’s Tale Season 6 episode this week? Here are all the details on potential new episodes of The Handmaid’s

The Realme GT 7 is the new battery life king in our lab tests

Realme launched the global GT 7 a few days ago at an event in Paris, France. It packs a 7,000 mAh Si/C battery, which is 200 mAh smaller than its Chinese counterpart, but still helped the smartphone become the new battery life king in our lab tests. Realme GT 7 5G We ran our standard

Rafael Mariano Grossi, the director-general of the International Atomic Energy Agency, speaks to journalists attending a weeklong seminar at the agency in Vienna, Austria, Wednesday, May 28, 2025.

Iranian FM vows cooperation following report on rising uranium stockpile : NPR

Rafael Mariano Grossi, the director-general of the International Atomic Energy Agency, speaks to journalists attending a weeklong seminar at the agency in Vienna, Austria, Wednesday, May 28, 2025. Jon Gambrell/AP hide caption toggle caption Jon Gambrell/AP DUBAI, United Arab Emirates — The Iranian Foreign Minister spoke by phone with the director of the U.N.’s nuclear

1880 Hong Kong club folds after 7 months, accused of owing staff unpaid wages

1880 Hong Kong club folds after 7 months, accused of owing staff unpaid wages

The Hong Kong branch of a Singapore-based private club, which recently closed its doors after only seven months of operation, has been accused of owing rent and more than 100 employees unpaid wages since April, with the Labour Department receiving requests for help from affected workers. 1880 Hong Kong, located at Swire Properties’ office complex

0
Would love your thoughts, please comment.x
()
x