21 August 2024

A novel phishing campaign targeting Android and iOS users


A novel phishing campaign targeting Android and iOS users

A new phishing campaign is targeting mobile banking users in the Czech Republic, exploiting Progressive Web Applications (PWAs) to steal banking credentials. The attack, uncovered by Slovak cybersecurity firm ESET, has already targeted clients of banks in Czechia, Hungary and Georgia.

The phishing campaign employs a variety of delivery mechanisms, including automated voice calls, SMS messages, and malvertising on social media platforms like Facebook and Instagram. Once a user is tricked, they are prompted to install a malicious PWA or WebAPK, depending on their device’s operating system.

PWAs are essentially websites packaged to appear as standalone apps.

On iOS, victims are guided to add the PWA to their home screen through a seemingly legitimate system prompt. On Android, the PWA is installed after the user confirms custom browser pop-ups.

The attackers also utilized social media platforms to spread their malicious software. By registering advertisements on Meta platforms, such as Facebook and Instagram, they could target specific demographics with offers to download fake banking app updates. These ads would appear in the victims' social media feeds, further legitimizing the phishing attempt.

The phishing technique was first disclosed by Poland’s CSIRT KNF in July 2023. In November 2023, ESET analysts observed the attack in the Czech Republic, specifically targeting clients of CSOB. Additionally, two similar campaigns were identified targeting OTP Bank in Hungary and TBC Bank in Georgia.

ESET's analysis believe that the observed campaigns are likely the work of two different threat actors, based on the command-and-control (C&C) servers and backend infrastructure involved.


Back to the list

Latest Posts

What is Vulnerability Management? A Beginner's Guide

What is Vulnerability Management? A Beginner's Guide

In this article will try to cover basics of vulnerability management process and why it is important to every company.
11 September 2024
Cyber Security Week in Review: September 6, 2024

Cyber Security Week in Review: September 6, 2024

In brief: the US charges Russian GRU hackers for attacks on Ukraine, Apache, Cisco, Zyxel patch high-risk flaws, Google fixes Android zero-day, and more.
6 September 2024
Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Threat actors using MacroPack Red Team framework to deploy Brute Ratel, Havoc and PhantomCore

Some of the documents appeared to be part of legitimate Red Team exercises, while other were intended for malicious purposes.
5 September 2024