talos · Crawled Aug 13, 2026
Curiouser and Curiouser
15 IoCs
Read original article ↗
AI Summary
Cisco Talos discovered 'JWR', a previously undocumented real-time phishing framework and likely variant of the 'The Outsider' phishing-as-a-service platform. JWR uses open WebSocket connections to enable attackers to monitor victim keystrokes in real time and dynamically guide them through fake login and checkout flows. The campaign is currently distributed via SMS lures impersonating regional toll and postal authorities, allowing threat actors to steal payment data, two-factor authentication (2FA) codes, identity documents, and device fingerprints.
AI-extracted · verify before operational use
Indicators of Compromise 15 extracted
| Type | Value | Detail |
|---|---|---|
| Filename | VID001.exe | Details → |
| Filename | tmp00055df5.dll | Details → |
| Filename | d4aa3e7010220ad1b458fac17039c274_62_Exe.exe | Details → |
| Filename | WCInstaller_NonAdmin.exe | Details → |
| Filename | SECOH-QAD.exe | Details → |
| SHA-256 | 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 | Details → |
| SHA-256 | 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 | Details → |
| SHA-256 | a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 | Details → |
| SHA-256 | c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 | Details → |
| SHA-256 | 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f | Details → |
| MD5 | 2915b3f8b703eb744fc54c81f4a9c67f | Details → |
| MD5 | c2efb2dcacba6d3ccc175b6ce1b7ed0a | Details → |
| MD5 | 7bdbd180c081fa63ca94f9c22c457376 | Details → |
| MD5 | 9a47c4d379998ade2f8f99e23a630c06 | Details → |
| MD5 | 38de5b216c33833af710e88f7f64fc98 | Details → |