This new phishing campaign uses a fake Google Account security page to steal passwords and more


  • Attackers abuse Progressive Web Apps (PWAs) on Android
  • Victims lured via phishing site google prism[dot]com to install malicious PWA
  • PWA harvests clipboard, crypto wallets, OTPs, GPS and more

Threat actors have started turning to Progressive Web Apps (PWA) to do their evil bidding on Android, stealing login credentials, cryptocurrency wallet data, GPS information and more, experts have warned.

Malwarebytes security researchers recently described one such campaign they saw in the wild, starting with a phishing email that lures people to a fake Google website google prism[dot]com.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top