As cited
Copy frozen at (site build).
threat intel
Dissecting the JWR phishing framework
Cisco Talos identified JWR, an undocumented phishing framework likely derived from the Outsider phishing-as-a-service platform, that harvests payment card data, identity documents, credentials, and device fingerprints through real-time operator control. The framework uses AES-CTR encrypted WebSocket connections and Vue.js interfaces to impersonate checkout and login pages for Shopify, PayPal, Apple, Klarna, and banks, while streaming victim keystrokes to the attacker in real time. Active campaigns targeting Southeast Asia and the Middle East deliver the JWR client via SMS lures impersonating toll authorities, postal services, and courier companies.
Why it matters: Organizations and individuals in Southeast Asia and the Middle East face active credential and payment data theft from operators using JWR; defenders should implement email and SMS security controls, educate users on URL verification, and monitor for Cisco Talos IOCs and ClamAV signatures to detect JWR deployments on compromised domains.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Dissecting the JWR phishing framework
Cisco Talos identified JWR, an undocumented phishing framework likely derived from the Outsider phishing-as-a-service platform, that harvests payment card data, identity documents, credentials, and device fingerprints through real-time operator control. The framework uses AES-CTR encrypted WebSocket connections and Vue.js interfaces to impersonate checkout and login pages for Shopify, PayPal, Apple, Klarna, and banks, while streaming victim keystrokes to the attacker in real time. Active campaigns targeting Southeast Asia and the Middle East deliver the JWR client via SMS lures impersonating toll authorities, postal services, and courier companies.
Why it matters: Organizations and individuals in Southeast Asia and the Middle East face active credential and payment data theft from operators using JWR; defenders should implement email and SMS security controls, educate users on URL verification, and monitor for Cisco Talos IOCs and ClamAV signatures to detect JWR deployments on compromised domains.
- Source published
- First seen by Cybersecurity Tracker