InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: Researchers expose PWA JavaScript attacks that redirect users to adult fraud apps
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > Researchers expose PWA JavaScript attacks that redirect users to adult fraud apps
Technology

Researchers expose PWA JavaScript attacks that redirect users to adult fraud apps

May 21, 2025 2 Min Read
Share
Researchers expose PWA JavaScript attacks that redirect users to adult fraud apps
SHARE

Cybersecurity researchers have discovered a new campaign that employs malicious JavaScript injection to redirect site visitors on mobile devices to Chinese Adult Content Progressive Web App (PWA) scams.

“The payload itself isn’t new (and yet another adult gambling scam), but the delivery method stands out,” C/Side researcher Himanshu Anand said in an analysis Tuesday.

“Malicious landing pages are full-fledged progressive web apps (PWAs), which are likely aimed at keeping users longer and bypassing basic browser protection.”

This campaign is designed to explicitly exclude desktop users, focusing primarily on mobile users. This activity is described as a client-side attack that uses third-party JavaScript and triggers only on mobile devices.

The use of PWA, a type of application built using web technology that provides a user experience similar to that of native apps built for a particular platform such as Windows, Linux, MacOS, Android, or iOS, is considered an attempt to avoid security protections.

Attacks involve injecting a website with JavaScript code that acts as a loader to trigger a redirect when a site is accessed from a device running on Android, iOS, iPads, etc.

Redirect is designed to direct users to adult content websites or other intermediary redirect page ad apps to display adult content. This page then takes the victim to a fake App Store list for Android and iOS apps in question.

“The use of PWA suggests that attackers are experimenting with more persistent phishing methods,” Anand said. “Mobile-only focus allows us to avoid many detection mechanisms.”

See also  Build an infrastructure for effective atmosphere coding in the enterprise
Share This Article
Twitter Copy Link
Previous Article Gears of War Reloaded release date, upgrades, etc. Gears of War Reloaded release date, upgrades, etc.
Next Article mm Why are AI chatbots often psychophonic?

Latest News

mm

Why LLMS is thinking too much about simple puzzles, but give up on hard puzzles

Artificial intelligence has made incredible advances with large-scale language models…

June 15, 2025
JSFireTruck JavaScript Malware

Over 269,000 websites infected with JSFiretruck JavaScript malware

Cybersecurity researchers are paying attention to "large campaigns" that undermine…

June 15, 2025
You need to know what features you need with 6 new ChatGPT projects

You need to know what features you need with 6 new ChatGPT projects

The ChatGPT project has just received the most significant update…

June 14, 2025
AsyncRAT and Skuld Stealer

Discord Invite Link Hijacking offers Asyncrat and Skuld Stealer targeted at crypto wallets

The new malware campaign is taking advantage of the weaknesses…

June 14, 2025
mm

The future of advertising after AI traffic coup

Large-scale language models are steadily replacing traditional searches by not…

June 13, 2025

You Might Also Like

Top 10 Best Practices for Effective Data Protection
Technology

Top 10 Best Practices for Effective Data Protection

12 Min Read
Clouds with AzureChecker
Technology

Storm-1977 uses Azurechecker to hit the education cloud and deploy over 200 crypto mining vessels

2 Min Read
mm
Technology

Recover and edit human images with AI

15 Min Read
Zero-click AI vulnerability exposes Microsoft 365 Copilot data without user interaction
Technology

Zero-click AI vulnerability exposes Microsoft 365 Copilot data without user interaction

9 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?