talos · Crawled Aug 13, 2026

Dissecting the JWR phishing framework

7 IoCs
Read original article ↗

AI Summary

Cisco Talos identified a new phishing framework named JWR, likely a variant of the 'Outsider' PhaaS platform, used in active smishing campaigns targeting users in Southeast Asia and the Middle East. The framework enables real-time, operator-driven session manipulation via AES-CTR encrypted WebSocket connections, allowing threat actors to harvest payment data, login credentials, 2FA codes, identity documents, and full device fingerprints. The client engine uses Vue.js to render 44 phishing pages and supports live keystroke streaming, enabling actors to monitor victim input as it is typed. The campaign delivers the phishing kit via SMS lures impersonating toll, postal, and courier services, with operator interfaces in Simplified Chinese, indicating a Chinese-speaking actor.

AI-extracted · verify before operational use

Indicators of Compromise 7 extracted

Type Value Detail
Filename static/js/ws-worker.js Details →
Filename a_index.html Details →
Domain api/open/addClick Details →
Domain api/open/getSyncSettings Details →
Domain api/open/pollInstruction Details →
Domain api/open/the_final_interface Details →
Domain api/open/addCvv Details →