Fake Google Security Alert Installs PWA That Steals MFA Codes
A phishing campaign uses google-prism.com to install a fake Google security PWA that steals MFA codes via WebOTP API, exfiltrates GPS and contacts, and acts as a browser RAT.
Mar 3, 20264 min read