Cybersecurity researchers have uncovered a sophisticated campaign using malicious JavaScript injections to redirect mobile users to Chinese adult-content scams disguised as Progressive Web Apps (PWAs).
“While the payload itself is nothing new (yet another adult gambling scam), the delivery method stands out,” explains c/side researcher Himanshu Anand. “The malicious landing page is a full-blown Progressive Web App, likely aiming to retain users longer and bypass basic browser protections.”
The attack specifically targets mobile device users while filtering out desktop traffic. This client-side attack leverages third-party JavaScript that activates exclusively on mobile platforms.
PWAs—applications built with web technologies that mimic native app experiences—are being exploited to circumvent standard security measures. The attack works by injecting websites with JavaScript code that functions as a loader, triggering redirections when accessed from Android, iOS, or iPadOS devices.
Users are directed to adult content websites or intermediate pages advertising adult content viewing apps. These pages then lead victims to fake app store listings for supposed Android and iOS applications.
“The use of PWAs suggests attackers are experimenting with more persistent phishing methods,” Anand notes. “The mobile-only focus allows them to evade many detection mechanisms.”
