Skip to content
Fake Google Security Site Deploys Malicious PWA to Steal User Data

Fake Google Security Site Deploys Malicious PWA to Steal User Data

First seen 3 Mar 2026, 14:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A phishing campaign is utilizing a counterfeit Google Account security page to distribute a malicious Progressive Web App (PWA). This app is designed to steal one-time passcodes, cryptocurrency wallet addresses, and user location data by tricking victims into believing they are interacting with a legitimate Google service. The attack exploits social engineering tactics to install the malware through users' browsers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

Timeline

2026-03-02
Bleepingcomputer reports on the phishing campaign
2026-03-03
Windowsreport publishes details on the malicious PWA

More articles in this cluster (3)