{
  "name": "Be careful what you wish for \u2013 Phishing in PWA applications",
  "slug": "be-careful-what-you-wish-for-phishing-in-pwa-applications",
  "description": "ESET analysts dissected a novel phishing method tailored to Android and iOS users, combining standard phishing delivery techniques with a novel approach of targeting mobile users via Progressive Web Applications (PWAs) and WebAPKs. Insidiously, installing these phishing PWAs and WebAPKs does not trigger warnings about installing third-party applications. Most of the observed applications targeted clients of Czech banks, but some also targeted banks in Hungary and Georgia. Two different threat actors were determined to be operating the campaigns based on their distinct command-and-control infrastructures.",
  "published": "2024-08-21T16:09:40+00:00",
  "created_at": "2024-08-21T16:09:40+00:00",
  "modified_at": "2024-08-21T16:27:59+00:00",
  "created_at_opencti": "2024-08-21T16:09:40+00:00",
  "author": "",
  "confidence": null,
  "report_types": [],
  "labels": [],
  "tags": [
    "2024-08-21",
    "android"
  ],
  "related_entities": {
    "observables": [
      {
        "id": "",
        "name": "185.68.16.56"
      },
      {
        "id": "",
        "name": "46.175.145.67"
      },
      {
        "id": "",
        "name": "185.181.165.124"
      },
      {
        "id": "",
        "name": "csas.georgecz.online"
      },
      {
        "id": "",
        "name": "play-protect.pro"
      },
      {
        "id": "",
        "name": "hide-me.online"
      },
      {
        "id": "",
        "name": "cyrptomaker.info"
      },
      {
        "id": "",
        "name": "blackrockapp.eu"
      }
    ],
    "attack_patterns": [
      {
        "id": "cc645def-9b23-446a-a343-ff285caa1a9e",
        "name": "T1437"
      },
      {
        "id": "e052d0a2-6d19-44f9-a843-2b372181b6a7",
        "name": "T1417"
      }
    ],
    "others": [
      {
        "id": "",
        "name": "South Georgia and the South Sandwich Islands"
      },
      {
        "id": "",
        "name": "Georgia"
      },
      {
        "id": "",
        "name": "Hungary"
      },
      {
        "id": "",
        "name": "Czechia"
      },
      {
        "id": "",
        "name": "Finance"
      }
    ]
  },
  "external_refs": [
    "https://www.welivesecurity.com/en/eset-research/be-careful-what-you-pwish-for-phishing-in-pwa-applications/",
    "https://otx.alienvault.com/pulse/66c62d64734f782122fa123b"
  ]
}