Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Researchers Expose PWA JavaScript Attack That Redirects Users to Adult Scam Apps

Posted on May 21, 2025May 21, 2025 By CWS

Could 21, 2025Ravie LakshmananMobile Safety / Browser Safety
Cybersecurity researchers have found a brand new marketing campaign that employs malicious JavaScript injections to redirect web site guests on cellular units to a Chinese language adult-content Progressive Internet App (PWA) rip-off.
“Whereas the payload itself is nothing new (one more grownup playing rip-off), the supply methodology stands out,” c/aspect researcher Himanshu Anand stated in a Tuesday evaluation.
“The malicious touchdown web page is a full-blown Progressive Internet App (PWA), doubtless aiming to retain customers longer and bypass fundamental browser protections.”
The marketing campaign is designed to explicitly filter out desktop customers, primarily specializing in cellular customers. The exercise has been described as a client-side assault that makes use of third-party JavaScript and solely triggers on cellular units.

The usage of PWAs, a sort of software constructed utilizing internet applied sciences that present a person expertise much like that of a local app constructed for a particular platform like Home windows, Linux, macOS, Android, or iOS, is seen as an try to sidestep safety protections.

The assaults contain injecting web sites with JavaScript code that acts as a loader to set off the redirection when the location is visited from units operating on Android, iOS, and iPadOS, amongst others.
The redirections are designed to steer the customers to grownup content material web sites or different middleman redirect pages promoting apps for viewing grownup content material. The pages subsequently take the victims to a faux app retailer itemizing for the supposed Android and iOS apps in query.
“The usage of PWAs suggests attackers are experimenting with extra persistent phishing strategies,” Anand stated. “The mobile-only focus permits them to evade many detection mechanisms.”

Discovered this text attention-grabbing? Observe us on Twitter  and LinkedIn to learn extra unique content material we submit.

The Hacker News Tags:Adult, Apps, Attack, Expose, JavaScript, PWA, Redirects, Researchers, Scam, Users

Post navigation

Previous Post: Ransomware Attack Forces Kettering Health to Cancel Procedures
Next Post: Up to 25% of Internet-Exposed ICS Are Honeypots: Researchers

Related Posts

Mustang Panda Deploys SnakeDisk USB Worm to Deliver Yokai Backdoor on Thailand IPs The Hacker News
Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk The Hacker News
Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networks The Hacker News
New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login The Hacker News
Türkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers The Hacker News
Microsoft August 2025 Patch Tuesday Fixes Kerberos Zero-Day Among 111 Total New Flaws The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials
  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
  • Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • China-Linked Hackers Exploit VMware ESXi Zero-Days to Escape Virtual Machines
  • xRAT Malware Attacking Windows Users Disguised as Adult Game
  • Fog Ransomware Attacking US Organizations Leveraging Compromised VPN Credentials
  • In Other News: 8,000 Ransomware Attacks, China Hacked US Gov Emails, IDHS Breach Impacts 700k
  • Threat Actors Attacking Systems with 240+ Exploits Before Ransomware Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark