Windowsreport
Fake Google Security Site Deploys Malicious PWA to Steal User Data
First seen 3 Mar 2026, 14:09 UTC
•

•29.2
Export
Article Content
Browse articles
A phishing campaign is utilizing a counterfeit Google Account security page to distribute a malicious Progressive Web App (PWA). This app is designed to steal one-time passcodes, cryptocurrency wallet addresses, and user location data by tricking victims into believing they are interacting with a legitimate Google service. The attack exploits social engineering tactics to install the malware through users' browsers.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-03-02
Bleepingcomputer reports on the phishing campaign
2026-03-03
Windowsreport publishes details on the malicious PWA
More articles in this cluster
Continue Reading
Google Addresses Eighth Chrome Zero-Day Vulnerability in 2025
Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities
Google Fixes 107 Security Flaws in Android Update
Google Chrome Zero-Day Vulnerability CVE-2025-13223 Exploited in the Wild
Sandworm Launches Wiper Malware Campaign Against Ukrainian Organizations
Apple Alerts Users of Targeted Mercenary Spyware Attacks in 110 Countries