{"success":true,"data":{"id":"pwa-silent-install","label":"Fake PWA or app install prompt impersonating a bank or Microsoft security update","description":"Fake Progressive Web App (PWA) install prompt impersonating a bank security update or Microsoft IT mandate. Attackers email victims urging them to \"click to install\" or \"add to home screen\" — the link triggers a PWA install that deploys a credential-harvesting fake bank or Microsoft 365 login with no app store review. The signal fires when: (1) an install CTA is present (click to install, add to home screen, one-click install) AND (2) brand-impersonation or security-mandate framing is present (banking app, Microsoft security update, organizational requirement) AND (3) the link does NOT point to a legitimate app store AND (4) no List-Unsubscribe header. Source: GC1 R13 council #3; Kaspersky PWA banking phish 2024; Cofense PWA enterprise Q1 2026.","tier":"warning","category":"other","isThin":false}}