Azat.Tv Phishing Scam Turns Browsers into Spying Tools for Google Users
Article Content
- •A phishing scam masquerades as a Google security check, targeting user trust.
- •The malicious site installs a Progressive Web App that can spy on users' devices.
- •Security experts advise users to be skeptical of unsolicited security alerts.
A new phishing scam is targeting users of Google services, tricking them into installing malware disguised as a security tool. The malicious site, operating under the domain google-prism[.]com, mimics a legitimate Google security verification page and prompts users to complete a four-step setup for account protection. This process leads to the installation of a Progressive Web App that can monitor clipboard activity, intercept one-time login codes, and track location data. Millions of users across both Android and desktop platforms are at risk, as the scam exploits user trust rather than software vulnerabilities. Security researchers recommend skepticism towards unsolicited security alerts and adherence to official protocols to mitigate risks. The campaign highlights a shift towards social engineering tactics in cybercrime, emphasizing the need for enhanced user awareness and security practices.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…