Categories: Analysis

Criminals are using progressive web apps to launch new phishing scams

Security researchers have identified a new phishing technique that uses progressive web applications (PWAs) to target customers of banks in Eastern Europe.

editorial

This content was selected, created and edited by the Finextra editorial team based on its relevance and interest to our community.

PWAs are essentially websites that resemble applications that can be installed without informing the user that they are third-party apps.

Researchers at ESET say fraudsters are targeting iOS and Android users with PWAs masquerading as banking apps.

The phishers use automated voice calls, SMS messages, and social media malvertising to trick iOS into instructing victims to add a PWA to their home screens, while on Android, the PWA installs after confirming custom pop-ups in the browser.

“At this point, these phishing apps on both operating systems are largely indistinguishable from the real banking apps they imitate,” says one ESET blog.

According to ESET, most of the identified phishing apps targeted customers of Czech banks, but one was against a Hungarian bank and another against a Georgian bank.

Additionally, there appear to be two different groups responsible for the apps. ESET warns: “We expect more copycat apps to be created and distributed because once installed, it is difficult to separate the legitimate apps from the phishing apps.”

David Brooks

Recent Posts

Northern Trust launches a blockchain-based carbon credit ecosystem

Asset manager Northern Trust has launched a blockchain-based platform that gives institutional buyers digital access…

5 hours ago

EToro USA will no longer offer trading in most cryptocurrencies following its settlement with the SEC

US-based social investing platform eToro has agreed to pay $1.5 million and halt trading in…

11 hours ago

Mastercard agrees to a $2.65 billion deal to buy threat intelligence giant Recorded Future

Mastercard has closed a deal to buy threat intelligence specialist Recorded Future from private equity…

17 hours ago

Google PaLM 2 AI model is under review by the Irish Data Protection Commission

As the national independent authority in Ireland, the Data Protection Commission (DPC) is responsible for…

23 hours ago

BBVA expands crypto asset service in Switzerland with USDC

The Swiss branch of Spanish bank BBVA is expanding its cryptocurrency custody and trading services…

1 day ago

The Church of England is completing its nationwide rollout of contactless donation devices

The Church of England has completed a three-year project to introduce contactless giving devices to…

1 day ago

This website uses cookies.