Scammers owners smartphone into revealing their personal information by clicking on push notifications that look like legitimate messages from well-known companies. The messages direct recipients to phishing pages, where they will be asked to enter their credentials, according to a new fraud technique that mobile phone monitoring company Lookout has identified in recent months.

The researchers noted that hackers are exploiting people's willingness to trust their mobile devices. Lookout detected a phishing campaign in which attackers created a Chrome notification alerting them to a missed call. They also pointed out an example of how hackers could illegally use logos from trusted companies like Slack to make a push notification appear legitimate.
If you click on the push notification, attackers can spoof well -known apps.
Mobile users cannot hover over a URL and typically cannot read the full website address like they can from a desktop computer, meaning attackers can more easily replace a legitimate website with a malicious destination. Social media apps like Facebook also have difficulty understanding users’ destinations on the website, so a realistic request for a person’s credentials is more likely to be effective.
