Skip to content
Phishing Scam Turns Browsers into Spying Tools for Google Users

Phishing Scam Turns Browsers into Spying Tools for Google Users

First seen 21 Mar 2026, 21:25 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 22, 2026 at 20:58 UTC
  • •A phishing scam masquerades as a Google security check, targeting user trust.
  • •The malicious site installs a Progressive Web App that can spy on users' devices.
  • •Security experts advise users to be skeptical of unsolicited security alerts.

A new phishing scam is targeting users of Google services, tricking them into installing malware disguised as a security tool. The malicious site, operating under the domain google-prism[.]com, mimics a legitimate Google security verification page and prompts users to complete a four-step setup for account protection. This process leads to the installation of a Progressive Web App that can monitor clipboard activity, intercept one-time login codes, and track location data. Millions of users across both Android and desktop platforms are at risk, as the scam exploits user trust rather than software vulnerabilities. Security researchers recommend skepticism towards unsolicited security alerts and adherence to official protocols to mitigate risks. The campaign highlights a shift towards social engineering tactics in cybercrime, emphasizing the need for enhanced user awareness and security practices.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 202d ago How this analysis works

Timeline

2026-03-21
Foxnews and Azat.Tv report on phishing scam targeting Google users.
2026-03-21
Malwarebytes identifies the phishing site google-prism[.]com.

More articles in this cluster (3)