Hackers steal banking creds from iOS, Android users via PWA apps

Hackers steal banking creds from iOS, Android users via PWA apps

Threat actors started to use progressive web applications to impersonate banking apps and steal credentials from Android and iOS users.

Progressive web apps (PWA) are cross-platform applications that can be installed directly from the browser and offer a native-like experience through features like push notifications, access to device hardware, and background data syncing.

Using this type of apps in phishing campaigns allows evading detection, bypass app installation restrictions, and gain access to risky permissions on the device without having to serve the user a standard prompt that could raise suspicion.

The technique was first observed in the wild in July 2023 in Poland, while a subsequent campaign that launched in November of the same year targeted Czech users.

Cybersecurity company ESET reports that it is currently tracking two distinct campaigns relying on this technique, one targeting the Hungarian financial institution OTP Bank and the other targeting TBC Bank in Georgia.

However, the two campaigns appear to be operated by different threat actors. One uses a distinct command and control (C2) infrastructure to receive stolen credentials, while the other group logs stolen data via Telegram.

Infection chain

ESET says that the campaigns rely on a broad range of methods to reach their target audience, including automated calls, SMS messages (smishing), and well-crafted malvertising on Facebook ad campaigns.

In the first two cases, the cybercriminals trick the user with a fake message about their banking app being outdated and the need to install the latest version for security reasons, providing a URL to download the phishing PWA.

PWA campaigns infection flow
PWA campaigns infection flow
Source: ESET

In the case of malicious advertisements on social media, the threat actors use the impersonated bank’s official mascot to induce a sense of legitimacy and promote limited-time offers like monetary rewards for installing a supposedly critical app update.

One of the malicious ads used in the phishing campaign
One of the malicious ads used in the phishing campaign
Source: ESET

Depending on the device (verified via the User-Agent HTTP header), clicking on the ad takes the victim to a bogus Google Play or App Store page.

Fake Google Play portal
Fake Google Play installation prompt (left) and progress (right)
Source: ESET

Clicking on the ‘Install’ button prompts the user to install a malicious PWA posing as a banking app. In some cases on Android, the malicious app is installed in the form of a WebAPK – a native APK generated by Chrome browser.

The phishing app uses the official banking app’s identifiers (e.g. logo legitimate-looking login screen) and even declares Google Play Store as the software source of the app.

The malicious WebAPK on the victim's homescreen and the phishing login page
The malicious WebAPK (left) and the phishing login page (right)
Source: ESET

The appeal of using PWAs on mobile

PWAs are designed to work across multiple platforms, so attackers can target a broader audience through a single phishing campaign and payload.

The key benefit, though, lies in bypassing Google’s and Apple’s installation restrictions for apps outside the official app stores, as well as “install from unknown sources” warning prompts that could alert victims to potential risks.

PWAs can closely mimic the look and feel of native apps, especially in the case of WebAPKs, where the browser logo on the icon and the browser interface within the app are hidden, so distinguishing it from legitimate applications is nearly impossible.

PWA (left) and legitimate app (right). WebAPKs are indistinguishable
PWA (left) and legitimate app (right). WebAPKs are indistinguishable as they lose the Chrome logo from the icon.
Source: ESET

These web apps can get access to various device systems through browser APIs, such as geolocation, camera, and microphone, without requesting them from the mobile OS’s permissions screen.

Ultimately, PWAs can be updated or modified by the attacker without user interaction, allowing the phishing campaign to be dynamically adjusted for greater success.

Abuse of PWAs for phishing is a dangerous emerging trend that could gain new proportions as more cybercriminals realize the potential and benefits.

A few months back, we reported about new phishing kits targeting Windows accounts using PWAs. The kits were created by security researcher mr.d0x specifically to demonstrate how these apps could be used to steal credentials by creating convincing corporate login forms.

BleepingComputer has contacted both Google and Apple to ask if they plan to implement any defenses against PWAs/WebAPKs, and we will update this post with their responses once we hear back.

Source link

Visited 1 times, 1 visit(s) today

Related Article

artist image of young star system

Water Discovered Around a Young, Sun-Like Star For First Time : ScienceAlert

For decades it was thought that water was prevalent in the outer reaches of the Solar System early in its history, with comets and asteroids delivering moisture to Earth and the inner planets during the Late Heavy Bombardment period around 4 billion years ago. An abundance of ice in places like the Kuiper Belt –

Hong Kong woman, 23, arrested on suspicion of doxxing ex-boyfriend

Hong Kong woman, 23, arrested on suspicion of doxxing ex-boyfriend

A 23-year-old woman has been arrested for allegedly disclosing the personal information of her former boyfriend after he dated someone else, Hong Kong’s privacy watchdog has said. The Office of the Privacy Commissioner for Personal Data apprehended the woman in the New Territories on Tuesday on suspicion of contravening the Personal Data (Privacy) Ordinance, following

Russian President Vladimir Putin.(AFP)

Putin’s sickening statistic: 1m Russian casualties in Ukraine | World News

JUNE IS turning into an ill-fated month for Russia’s armed forces. It started with a daring Ukrainian drone attack on airfields stretching from Siberia in the east to Murmansk in the north that Ukraine claims destroyed 41 large planes, or about one-third of Russia’s strategic bomber fleet. But another, more momentous, statistic looms. Before the

混血肥仔丁丁同遊越南被捕獲 發文強調「同幾個朋友去越南玩幾日啫」 | am730

混血肥仔丁丁同遊越南,意外被捕獲。 YouTuber混血肥仔與被爆偷食公司女主持丁彥均(丁丁)。事件曝光後,丁丁發聲明指沒有介人別人婚姻,而混血肥仔則發文,稱與太太芊蕙子已簽分居協議書,但芊蕙子就表示從未收到混血肥仔或律師提交的離婚呈請,更大爆男方在去年10月親口承認婚內出軌。 混血肥仔與丁丁遊越南被捕獲 近日有網民發現在一越南YouTuber的影片中見到混血肥仔與丁丁影踪。影片見到該名YouTuber正與兩位女士在戶外點餐,而混血肥仔與丁丁就在他們身旁行過,而該名YouTuber更讚丁丁靚女:「美女啊,桃花眼睛啊,哎呀真不錯啊,長的真的不錯啊,巴拉圭牛仔裙那個啊。」丁丁就一手插袋,並與混血肥仔並肩而行,男方就拿住一袋二袋。 混血肥仔:同幾個朋友去越南玩幾日啫 混血肥仔見有關影片在討論區引來熱烈討論之後,便火速在IG回應,他寫道:「唔出聲又會俾人老作,上星期放假同幾個朋友去越南玩幾日啫,我已經返到英國了,咁都俾人影到真係笑死。之前已經有好多報道做成好多傷害,好多人可以講好多嘢落井下石,好不容易大家走出了情緒低谷,唔一定要支持嘅,大家繼續好好生活就可以了。」 他亦轉發了另一朋友的限時動態,對方貼出在越南一間餐廳的黑白環境照,寫著:「唔知講咩好,但誠意推薦呢間嘅蛋咖啡,好!好!味!啊!」並標註了混血肥仔和丁丁,似乎是想告訴給大家知越南之旅並非只得兩個人。 他亦轉發了另一朋友的限時動態,對方貼出在越南一間餐廳的黑白環境照,寫著:「唔知講咩好,但誠意推薦呢間嘅蛋咖啡,好!好!味!啊!」並標註了混血肥仔和丁丁,似乎是想告訴給大家知越南之旅並非只得兩個人。 立即更新/下載AM730手機APP 體驗升級功能 Source link

2 global conferences to make Hong Kong debut this month: John Lee

2 global conferences to make Hong Kong debut this month: John Lee

Two international conferences will be held in Hong Kong for the first time this month, Chief Executive John Lee Ka-chiu has said, pledging that authorities will continue to attract more events to bring in high-end tourists and enhance the city’s global network. The city leader said on Tuesday that several global conferences had made their

India Foreign Exchange Market Valuation to Reach USD 65.8

India Foreign Exchange Market Valuation to Reach USD 65.8

India Foreign Exchange Market 2025-2033 According to IMARC Group’s report titled “India Foreign Exchange Market Size, Share, Trends and Forecast by Counterparty, Type, and Region, 2025-2033”, The report offers a comprehensive analysis of the industry, including market share, growth, trends, and regional insights. How Big is the India Foreign Exchange Industry ? The India foreign

Barcelona Transfer DealSheet: Early targets, potential sales and La Liga limits

Barcelona’s plans for the transfer market tend to come with several caveats — as followers of the Dani Olmo registration drama last season will recall. Hansi Flick’s side had a brilliant season, beating Real Madrid in the two domestic finals and the title race to complete a domestic treble, while also reaching the Champions League

Why ‘Taylor Swift & Blake Lively Fighting’ Is Trending?

Wondering why “Taylor Swift & Blake Lively fighting” is trending online? After legal drama involving Justin Baldoni and dropped subpoenas, reports suggest a fallout between the longtime friends. With fans speculating and insider details emerging, questions about their friendship continue to grow. Here’s what we know about the reported rift, legal tensions, and what led

A screen grab of CCTV footage circulating online shows the robber holding a knife at the bank worker’s throat. Photo: Handout

Suspect in Hong Kong bank robbery believed to have fled to mainland China

An armed robber, who triggered a manhunt after he held a woman at knifepoint and stole HK$370,000 (US$47,180) from a Hang Seng Bank branch, is a Hongkonger and has fled across the border, the Post has learned. A source said on Tuesday that police’s elite tactical unit, the Flying Tiger, was searching for the local

Hamas-run health ministry says many killed while waiting for aid in Rafah - live updates

Hamas-run health ministry says many killed while waiting for aid in Rafah – live updates

Fatalities after crowd fired on near Gaza aid hub – reportspublished at 06:46 British Summer Time 06:46 BSTBreaking Barbara Plett UsherReporting from Jerusalem In the past few minutes, reports have started to emerge of another fatal incident near a distribution centre in Hamas-controlled Gaza. Civil Defense Agency spokesman Mahmoud Bassal says Israeli troops killed 19

How Hong Kong’s Soy Story Blends Tradition and Innovation

Two chefs, one unlikely main ingredient. The simple soybean takes the spotlight at both One-MICHELIN-Star Mora and Bib Gourmand Kung Wo Beancurd Factory. On one end of the culinary spectrum is executive chef Ming Fai Choi (winner of the MICHELIN Young Chef Award Hong Kong & Macau 2024) of Mora, who reimagines soy through a

PwC Faces Partner Exodus In Hong Kong Amid China Audit Issues

PwC Faces Partner Exodus In Hong Kong Amid China Audit Issues

What’s going on here? PwC’s Hong Kong operations are in turmoil as a wave of partner departures follows audit complications with China Evergrande and pivotal client losses. What does this mean? PwC is grappling with internal discord as audit-related issues with China Evergrande lead to a significant exodus of partners. In the last six months,

Exclusive: Here’s our first look at NxtQuantum’s AI+ Nova 2 5G smartphone

Last week, we learned that AI+, a smartphone brand part of NxtQuantum Shift Technologies led by Madhav Sheth, will launch its first smartphone by the end of June. And yesterday, the brand announced that it would launch its Nova series 5G smartphones in India on June 25 without revealing the names or specs of the

China And Hong Kong Stocks Climb With Banking And Auto Gains

China And Hong Kong Stocks Climb With Banking And Auto Gains

What’s going on here? On June 3, 2025, China and Hong Kong markets experienced gains, driven primarily by banking and automotive sectors, even as cautious investor sentiment lingered ahead of critical trade discussions. What does this mean? China’s main stock indices, including the blue-chip CSI300 and the Shanghai Composite, rose 0.5% by midday, rebounding from

混血肥仔反擊與丁丁遊越南 「唔出聲又會俾人老作」 | 娛樂 on LINE

混血肥仔被發現與丁丁遊越南,火速出限時動態回應。 YouTuber混血肥仔(曾達恩Tommy)今年2月爆出疑背妻出軌後,事業幾近停擺,連有份主持的ViuTV《香港達人秀》亦延期至今仍未播出。4月時混血肥仔在英國時間生日正日上載自拍照,寫道:「生日晚飯一人前。Birthday dinner for one,Wishing peace and happiness to you all」。強調自己一個人吃生日晚餐,並祝大家平安幸福。日前有越南YouTuber於餐廳室外位置拍下與兩位女士點餐的情況,剛巧混血肥仔與丁丁在他們身旁行過,該名YouTuber更讚丁丁靚女:「美女啊,桃花眼睛啊,哎呀真不錯啊,長的真的不錯啊,巴拉圭牛仔裙那個啊。」當時拍到一手插袋的丁丁與混血肥仔並肩而行。 越南YouTuber於餐廳室外位置大讚丁丁靚女。 一手插袋的丁丁與混血肥仔並肩而行。 混血肥仔IG限時動態火速回應 混血肥仔和丁丁現身越南的影片在網上迅速引起討論,混血肥仔火速上在IG限時動態回應,寫道:「唔出聲又會俾人老作,上星期放假同幾個朋友去越南玩幾日啫,我已經返到英國了,咁都俾人影到真係笑死。之前已經有好多報道做成好多傷害,好多人可以講好多嘢落井下石,好不容易大家走出了情緒低谷,唔一定要支持嘅,大家繼續好好生活就可以了。」 混血肥仔火速上在IG限時動態回應。 混血肥仔之後再轉發另一朋友的限時動態,對方貼出在越南一間餐廳的黑白環境照,並標註混血肥仔和丁丁,寫著:「唔知講咩好,但誠意推薦呢間嘅蛋咖啡,好!好!味!啊!」。混血肥仔似乎想力證這次越南之旅並非只得他和丁丁兩人。 混血肥仔再轉發另一朋友的限時動態。 今年2月,混血肥仔被拍到與丁丁撐檯腳,更傳兩人拖手。其妻芊蕙子在IG限時動態若有所指,丁丁指自己不涉介入他人婚姻,並決定暫時退出幕前工作。芊蕙子其後稱尚未簽任何離婚文件,爆混血肥仔去年親認婚內出軌。而混血肥仔列出4點回應出軌指控,指芊蕙子去年2月表示希望離婚,最終簽下分居協議書。混血肥仔透露在簽署分居協議書後,曾經嘗試了解其他對象,但最後都沒有發展成任何親密關係,他亦指芊蕙子要求他在期限之前把物業轉讓到她名下。 混血肥仔與丁丁年初被捕獲疑似拖手拍拖。 丁丁曾發文澄清沒有介入別人婚姻關係。 混血肥仔以黑圖出文回應。 混血肥仔今年4月上載獨自慶生自拍照。 混血肥仔與太太芊蕙子育有兩名女兒。 混血肥仔返英獨自慶生 「生日晚飯一人前」 芊蕙子稱尚未簽任何離婚文件 爆混血肥仔去年親認婚內出軌 混血肥仔承認分居後曾了解其他對象 太太要求期限前將物業轉名 丁丁認已互相了解 有確認混血肥仔和太太已簽紙分開 Source link

Hong Kong’s John Lee cites ‘good understanding’ in meetings with new liaison chief

Hong Kong’s John Lee cites ‘good understanding’ in meetings with new liaison chief

Hong Kong’s leader has attributed his two meetings with Beijing’s newly appointed liaison office chief within three days to the need to maintain good communication and understanding with the central government, so he can reflect the city’s situation accurately and formulate good policies. Chief Executive John Lee Ka-chiu on Tuesday described Zhou Ji, the new

ET logo

Rupee declines 10 paise to 85.49 against US dollar in early trade

The rupee depreciated 10 paise to 85.49 against the US dollar in early trade on Tuesday amid a slight recovery in the American currency against major rivals, higher crude oil prices and outflow of foreign funds. Volatile domestic equity markets ahead of the Reserve Bank’s monetary policy announcements also weighed on the Indian currency, forex

0
Would love your thoughts, please comment.x
()
x