HomeSecurityFake Google Security site steals MFA codes

Fake Google Security site steals MFA codes

A new phishing uses a fake Google Security Account to deliver a PWA app that steals passwords, MFA codes, and cryptocurrency wallet addresses. The attack leverages Progressive Web Apps and social engineering to trick users into thinking they are interacting with a legitimate Google. This tactic represents a significant evolution in phishingas attackers turn to more sophisticated methods that bypass traditional security measures.

See also: Starkiller: New phishing kit bypasses MFA

Google Security
Fake Google Security site steals MFA codes

Cybercriminals are using the domain google-prism[.]com, which is presented as a legitimate Google Security, displaying a four-step installation process that involves granting dangerous permissions and installing the malicious PWA app. In some cases, the website also promotes a companion Android app to “protect” contacts. The choice of domain is particularly cunning, as the name “prism” is associated with surveillance and security programs, creating a false sense of legitimacy for defensive users.

According to researchers at cybersecurity firm Malwarebytes, the PWA app can extract contacts, GPS , and clipboard contents. Additional functionality observed includes acting as a network proxy and internal port scanner, allowing the attacker to route requests through the victim's browser and detect active hosts on the network. These capabilities make the attack particularly dangerous for corporate environments, where access to internal networks can lead to a massive data breach.

Technical details of the attack

The website also requests permissions to access text and images copied to the clipboard, which can only happen when the app is open. However, the fake website also requests permission to display notifications, allowing the attacker to send notifications, new tasks, or trigger data extraction. The key to the success of this tactic is that PWAs appear as standalone applications without the browser address bar, making it difficult for users to recognize that they are interacting with malicious content.

Additionally, the malware uses the WebOTP API in supported browsers in an attempt to intercept SMS and checks /api/heartbeat every 30 seconds for new commands. Since the PWA application can only steal clipboard contents and OTP when it is open, notifications can be used to send fake security alerts that prompt the user to reopen the PWA. This strategy ensures continuous access to the victim’s data, even when the user is not actively using the application.

See also: MFA is required for logins to the Microsoft 365 admin center

Fake Google Security site steals MFA codes
Fake Google Security site steals MFA codes

Malwarebytes says the focus is on stealing one-time passwords (OTPs) and cryptocurrency wallet addresses, and that the malware also creates a detailed device fingerprint. Another component in the malicious PWA is a service worker that is responsible for push notifications, executing tasks from downloaded payloads, and preparing stolen data locally for export. The device fingerprint collected includes information such as the operating system, browser version, installed extensions, and other characteristics that can be used for future targeted attacks.

Protection measures and security recommendations

To protect against these types of attacks, experts recommend educating users about the risks of PWAs and avoiding installing unknown “apps” from websites. Organizations should implement behavioral analysis beyond traditional email authentication checks and monitor for redirect chains that include Google Cloud. Additionally, using browser extensions that block PWAs or disabling them through browser settings can provide additional protection.

Because the worker includes a handler for Periodic Background Sync , which allows web applications in Chromium- based browsers to periodically synchronize data in the background, an attacker can log in to a compromised device as long as the malicious PWA application is installed. This makes it especially important to promptly remove such applications when detected.

See also: ownCloud urges users to enable MFA

Fake Google Security site steals MFA codes
Fake Google Security site steals MFA codes

Users who choose to enable all security features for their account also receive an APK for Android devices that promises to extend protection to their contact list.

Source: bleepingcomputer

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS