talos · Crawled Aug 13, 2026

Curiouser and Curiouser

15 IoCs
Read original article ↗

AI Summary

Cisco Talos discovered 'JWR', a previously undocumented real-time phishing framework and likely variant of the 'The Outsider' phishing-as-a-service platform. JWR uses open WebSocket connections to enable attackers to monitor victim keystrokes in real time and dynamically guide them through fake login and checkout flows. The campaign is currently distributed via SMS lures impersonating regional toll and postal authorities, allowing threat actors to steal payment data, two-factor authentication (2FA) codes, identity documents, and device fingerprints.

AI-extracted · verify before operational use

Indicators of Compromise 15 extracted

Type Value Detail
Filename VID001.exe Details →
Filename tmp00055df5.dll Details →
Filename d4aa3e7010220ad1b458fac17039c274_62_Exe.exe Details →
Filename WCInstaller_NonAdmin.exe Details →
Filename SECOH-QAD.exe Details →
SHA-256 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 Details →
SHA-256 90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59 Details →
SHA-256 a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 Details →
SHA-256 c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2 Details →
SHA-256 9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f Details →
MD5 2915b3f8b703eb744fc54c81f4a9c67f Details →
MD5 c2efb2dcacba6d3ccc175b6ce1b7ed0a Details →
MD5 7bdbd180c081fa63ca94f9c22c457376 Details →
MD5 9a47c4d379998ade2f8f99e23a630c06 Details →
MD5 38de5b216c33833af710e88f7f64fc98 Details →