Dissecting the JWR phishing framework
AI Summary
Cisco Talos identified a new phishing framework named JWR, likely a variant of the 'Outsider' PhaaS platform, used in active smishing campaigns targeting users in Southeast Asia and the Middle East. The framework enables real-time, operator-driven session manipulation via AES-CTR encrypted WebSocket connections, allowing threat actors to harvest payment data, login credentials, 2FA codes, identity documents, and full device fingerprints. The client engine uses Vue.js to render 44 phishing pages and supports live keystroke streaming, enabling actors to monitor victim input as it is typed. The campaign delivers the phishing kit via SMS lures impersonating toll, postal, and courier services, with operator interfaces in Simplified Chinese, indicating a Chinese-speaking actor.
AI-extracted · verify before operational use