Hackers steal banking creds from iOS, Android users via PWA apps

Hackers steal banking creds from iOS, Android users via PWA apps

Threat actors started to use progressive web applications to impersonate banking apps and steal credentials from Android and iOS users.

Progressive web apps (PWA) are cross-platform applications that can be installed directly from the browser and offer a native-like experience through features like push notifications, access to device hardware, and background data syncing.

Using this type of apps in phishing campaigns allows evading detection, bypass app installation restrictions, and gain access to risky permissions on the device without having to serve the user a standard prompt that could raise suspicion.

The technique was first observed in the wild in July 2023 in Poland, while a subsequent campaign that launched in November of the same year targeted Czech users.

Cybersecurity company ESET reports that it is currently tracking two distinct campaigns relying on this technique, one targeting the Hungarian financial institution OTP Bank and the other targeting TBC Bank in Georgia.

However, the two campaigns appear to be operated by different threat actors. One uses a distinct command and control (C2) infrastructure to receive stolen credentials, while the other group logs stolen data via Telegram.

Infection chain

ESET says that the campaigns rely on a broad range of methods to reach their target audience, including automated calls, SMS messages (smishing), and well-crafted malvertising on Facebook ad campaigns.

In the first two cases, the cybercriminals trick the user with a fake message about their banking app being outdated and the need to install the latest version for security reasons, providing a URL to download the phishing PWA.

PWA campaigns infection flow
PWA campaigns infection flow
Source: ESET

In the case of malicious advertisements on social media, the threat actors use the impersonated bank’s official mascot to induce a sense of legitimacy and promote limited-time offers like monetary rewards for installing a supposedly critical app update.

One of the malicious ads used in the phishing campaign
One of the malicious ads used in the phishing campaign
Source: ESET

Depending on the device (verified via the User-Agent HTTP header), clicking on the ad takes the victim to a bogus Google Play or App Store page.

Fake Google Play portal
Fake Google Play installation prompt (left) and progress (right)
Source: ESET

Clicking on the ‘Install’ button prompts the user to install a malicious PWA posing as a banking app. In some cases on Android, the malicious app is installed in the form of a WebAPK – a native APK generated by Chrome browser.

The phishing app uses the official banking app’s identifiers (e.g. logo legitimate-looking login screen) and even declares Google Play Store as the software source of the app.

The malicious WebAPK on the victim's homescreen and the phishing login page
The malicious WebAPK (left) and the phishing login page (right)
Source: ESET

The appeal of using PWAs on mobile

PWAs are designed to work across multiple platforms, so attackers can target a broader audience through a single phishing campaign and payload.

The key benefit, though, lies in bypassing Google’s and Apple’s installation restrictions for apps outside the official app stores, as well as “install from unknown sources” warning prompts that could alert victims to potential risks.

PWAs can closely mimic the look and feel of native apps, especially in the case of WebAPKs, where the browser logo on the icon and the browser interface within the app are hidden, so distinguishing it from legitimate applications is nearly impossible.

PWA (left) and legitimate app (right). WebAPKs are indistinguishable
PWA (left) and legitimate app (right). WebAPKs are indistinguishable as they lose the Chrome logo from the icon.
Source: ESET

These web apps can get access to various device systems through browser APIs, such as geolocation, camera, and microphone, without requesting them from the mobile OS’s permissions screen.

Ultimately, PWAs can be updated or modified by the attacker without user interaction, allowing the phishing campaign to be dynamically adjusted for greater success.

Abuse of PWAs for phishing is a dangerous emerging trend that could gain new proportions as more cybercriminals realize the potential and benefits.

A few months back, we reported about new phishing kits targeting Windows accounts using PWAs. The kits were created by security researcher mr.d0x specifically to demonstrate how these apps could be used to steal credentials by creating convincing corporate login forms.

BleepingComputer has contacted both Google and Apple to ask if they plan to implement any defenses against PWAs/WebAPKs, and we will update this post with their responses once we hear back.

Source link

Visited 1 times, 1 visit(s) today

Related Article

Deals: Moto Razr 60 and Razr 60 Ultra launch, Galaxy A36 and A56 get cheaper

This week, Motorola unveiled its new flip foldables, which boast dust resistance (IP48) – a rare feature on foldables. Also this week, Samsung’s mid-rangers drop even lower but there are some alluring alternatives. The Razrs first. The Motorola Razr 60 Ultra features a proper flagship chipset, the Snapdragon 8 Elite, unlike the “s” chip of

Explainer | How the coming new anti-smoking measures in Hong Kong will affect you

Explainer | How the coming new anti-smoking measures in Hong Kong will affect you

Hong Kong authorities have revealed more details on eight of the 10 tobacco control measures in an amended bill on Friday, including a ban on possessing alternative smoking products (ASPs) starting from April 30 next year. The sale of conventional smoking products with flavours other than menthol are also expected to be banned from the

The Studio Episode 7 Release Date, Time, Where to Watch

The Studio Episode 7 release date and time is right around the corner. The previous episode witnessed Matt’s ego being tested as his doctor girlfriend takes him to a charity gala. Furthermore, the upcoming episode, titled “Casting,” will see the continental team trying to come up with a film cast that won’t offend anyone. Here’s

Nearly 100 Hongkongers lose HK$90 million in 1 week through investment scams

Nearly 100 Hongkongers lose HK$90 million in 1 week through investment scams

Nearly 100 Hongkongers have been scammed out of HK$90 million (US$11.6 million) in just one week by online fraudsters posing as investment experts to lure victims into betting on cryptocurrency and stocks by offering fake insider knowledge and tips. One 84-year-old businessman suffered the largest single loss when he was deceived into investing in cryptocurrency,

Trump did not say when the call with the Chinese leader took place or specify what was discussed.(Reuters/File Image)

China denies trade talks with US despite Donald Trump’s claim | World News

Apr 26, 2025 01:56 PM IST The world’s two biggest economies are locked in an escalating tit-for-tat trade battle triggered by Trump’s levies on Chinese goods. China repeated Saturday that it had held no talks with the United States on trade issues, despite President Donald Trump’s claim that he had taken a call from Xi

FX Winning Reviews & News: Investors Can Trace Their Lost Funds

Investors Can Trace Their Lost Funds

InvestorWarnings.com has issued a new update on the FX Winning case. Trace Your Lost Funds Here: https://www.investorwarnings.com/warnings/get-expert-assistance-on-your-case/ Regulatory Warnings Against FX Winning In the dynamic and often volatile world of online trading, the importance of regulatory oversight cannot be overstated. Financial regulators across the globe play a critical role in protecting investors, maintaining fair markets,

Pope’s coffin sealed ahead of funeral on Saturday morning

Pope Francis’ life recalled in Deed placed in coffin

The Deed for the Pious Passing of His Holiness Pope Francis has been placed in his coffin, which was sealed in a solemn rite ahead of his Requiem Mass. By Vatican News The coffin of the late Pope Francis was sealed in a ritual in St. Peter’s Basilica on Friday evening, after around 250,000 pilgrims

A view of the Santa Maria Maggiore (St. Mary Major) Basilica in Rome

Watch Live: Pope Francis’ funeral set to begin as Vatican lays late pontiff to rest

The funeral service for Pope Francis is taking place Saturday morning at the Vatican, after which the late leader of the Catholic Church will be buried in Rome. While the ceremony will follow many traditions developed over centuries of church history, there will also be some details uniquely chosen by Pope Francis. Watch the ceremony live

2 injured after bamboo stick falls from scaffolding in Hong Kong

2 injured after bamboo stick falls from scaffolding in Hong Kong

Two men have been injured by a bamboo stick that fell from scaffolding outside an industrial building in Hong Kong, with one left bleeding from the incident. Hong Kong police said they were alerted shortly before 10am on Saturday about a man being hit on the forehead by a bamboo stick that fell from scaffolding

Who Is Carrie Preston’s Husband? Michael Emerson’s Job & Relationship History

Carrie Preston’s personal life is a topic of curiosity among fans, with many eager to learn about her husband. The actress has captivated audiences for years with her remarkable performances, including her Emmy-winning role as Elsbeth Tascioni on The Good Wife and her unique characters in Claws and other projects. Beyond her vibrant on-screen presence,

Trump Just Deported Another U.S. Citizen Child With Cancer

As part of Donald Trump‘s immigration crackdown, three U.S. citizen children were deported with their mothers by the New Orleans Immigration and Customs Enforcement (ICE) on Friday morning. One of the children was undergoing cancer treatment and one of the mothers is pregnant. Both families had lived in the country for years and had ties

Peter Yip Mow-lum, chairman of Bright Smart Securities, during an interview in Central on 19 June 2020. Photo: Xiaomei Chen

Ant Group buys retail broker Bright Smart to set up ‘bridgehead’ in Hong Kong’s market

Ant Group has bought control of Hong Kong’s largest retail stock brokerage, as mainland China’s dominant online-payment operator stakes out a foothold in Asia’s third-largest capital market amid a resurgence of initial public offerings (IPOs) and transactions. Ant Group agreed to pay HK$2.81 billion (US$362.2 million) for 50.55 per cent of Bright Smart Securities &

Hong Kong’s new tobacco control measures won’t affect tourists: official

Hong Kong’s new tobacco control measures won’t affect tourists: official

Tourists will be unaffected by Hong Kong’s new proposed control measures on tobacco products, an official has said, promising that such policies will strike a balance between protecting public health and the economy. Deputy Secretary for Health Eddie Lee Lik-kong said on Saturday that authorities had already taken tourists’ needs into account when drafting the

BlackRock not Buying into Ripple’s XRP

BlackRock not Buying into Ripple’s XRP

xrp-usd Market participants do not expect to see much activity from BlackRock with XRP ETFs Olumide Adesina•Saturday, April 26, 2025•1 min read Add an article to your Reading List Register now to be able to add articles to your reading list. ” aria-hidden=”true”> Quick overview Market participants believe BlackRock is currently focused on maximizing profits

0
Would love your thoughts, please comment.x
()
x