Push notifications in browsers as a means of phishing and advertising are gaining popularity, with the share of users experiencing this problem increasing dramatically over the year. As shown by recent Kaspersky research, the monthly number of affected users has increased from 1,722,545 in January to 5,544,530 in September 2019. 
Overall, in the first nine months of 2019, Kaspersky products protected more than 14,000,000 users from attempted breaches via unwanted notifications. With virtually every internet user a potential victim, this threat, while not at all sophisticated, requires extra attention.
Browser push notifications were introduced several years ago as a useful tool that kept readers informed with regular updates, but today they are often used to bombard website visitors with unsolicited ads or even encourage them to download malware.
Useful, user-friendly features like push notifications are easy tools for social engineering scams, so their growing popularity is not entirely unexpected. In light of the recent calendar invitation scam detected by Kaspersky, the company’s experts decided to delve deeper into push notification and phishing scams to learn how this tool can be abused.
Since user consent is required to initiate notifications, attackers have come up with multiple, often 'out of the box', ways to trick and force people into accepting such subscriptions. The options identified include:
- Obtaining consent under the guise of another action, such as CAPTCHA.
- Toggle "accept" and "reject" buttons on registration warnings.
- Display alerts from phishing copies of popular websites.
- Displaying misleading pop-ups on websites.
After obtaining the user’s consent, attackers begin to “bombard” them with messages. The least harmful (yet most popular) options are clickbait about sensitive social topics, while others include scam alerts – such as winning the lottery, offers of money in exchange for completing a survey, or something similar.
The most sophisticated systems aim to extort money from users through phishing techniques.
An example of a phishing alert that mimics a Microsoft Windows system update
A common scheme uses messages disguised as system notifications, such as warnings about a virus “infection.” These redirect users to phishing copies of trusted websites and then urge users to download various “PC cleaning” utilities. However, the capabilities of push notifications used for such scams are not limited to this.
“We have seen push notifications being abused as attackers continue to creatively adapt new technologies to trick users. Because this feature is so widespread and easy to exploit by social engineering systems, we have seen a rapid growth in the number of affected users. Push notifications are a very useful tool for users that help them stay informed about various important things that interest them. However, as with anything online, users should remain cautious and cautious when interacting with pop-ups and only allow push notifications if they are absolutely sure that the alerts are useful and come from trusted sources,” said Artemy Ovchinnikov, security researcher at Kaspersky.
To avoid receiving annoying notifications or fraudulent ads, users can follow a few simple tips:
- Where possible, block all subscription offers unless they come from popular and trusted websites. Remain vigilant to ensure you are not redirected to a fake website.
- If an unwanted subscription cannot be avoided, block it in your browser settings.
- Start using a reliable security solution that blocks subscription offers and push scams in browsers, can delete subscriptions that have already been approved, and has anti-phishing functionality.
More information can be found on Kaspersky's dedicated Securelist website

