This new phishing campaign uses a fake Google account security page to steal access codes and more.


  • Attackers abuse Progressive Web Apps (PWA) on Android
  • Victims lured via phishing site google-prism[dot]com in installing malicious PWAs
  • PWA harvests clipboard, crypto wallets, OTPs, GPS, etc.

Threat actors have started turning to Progressive Web Apps (PWAs) to run their dirty bidding on Android, stealing login credentials, cryptocurrency wallet data, GPS information, and more, experts have warned.

Security researchers at Malwarebytes recently detailed one such campaign they spotted in the wild, starting with a phishing email, luring people to a fake Google site google-prism[dot]com.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top