A sophisticated phishing campaign is currently using fake Google Account security pages to trick users into installing malicious Progressive Web Apps (PWAs). These apps are designed to steal login credentials and Multi-Factor Authentication (MFA) codes.
How the Attack Works
- The Lure: Victims are directed to a site that looks like a legitimate Google security warning.
- The PWA Trick: The site prompts you to “install” a security app. Since PWAs run in a standalone window without a browser address bar, it’s difficult to see that you are still on a malicious website.
- Data Theft: The app requests permissions for your Contacts and GPS Location while presenting a fake login screen to capture your password and MFA codes.
- Proxying: According to reports from BleepingComputer, these apps can even turn your browser into a proxy to route attacker traffic through your IP address.
How to Protect Yourself
- Check the URL: Real Google security settings are always located at myaccount.google.com.
- Avoid “Install” Prompts: Google will never ask you to install a standalone PWA to perform a security check.
- Audit Your Apps: On Android, go to Settings > Apps and uninstall anything suspicious like “Google Security Update” or “System Service.”
- Switch to Passkeys: Using Google Passkeys or a physical FIDO2 security key is the best way to block these real-time phishing attempts.