Fake Google Security Site Deploys Malicious PWA to Steal User Data

Fake Google Security Site Deploys Malicious PWA to Steal User Data

First seen 3 Mar 2026, 14:09 UTC BleepingcomputerWindowsreportScworld 29.2

Article Content

Browse articles
ThreatCluster

A phishing campaign is utilizing a counterfeit Google Account security page to distribute a malicious Progressive Web App (PWA). This app is designed to steal one-time passcodes, cryptocurrency wallet addresses, and user location data by tricking victims into believing they are interacting with a legitimate Google service. The attack exploits social engineering tactics to install the malware through users' browsers.

Timeline

2026-03-02
Bleepingcomputer reports on the phishing campaign
2026-03-03
Windowsreport publishes details on the malicious PWA