CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Permanent story citation

Dissecting the JWR phishing framework

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4401

As cited

Copy frozen at (site build).

threat intel

Dissecting the JWR phishing framework

Cisco Talos identified JWR, an undocumented phishing framework likely derived from the Outsider phishing-as-a-service platform, that harvests payment card data, identity documents, credentials, and device fingerprints through real-time operator control. The framework uses AES-CTR encrypted WebSocket connections and Vue.js interfaces to impersonate checkout and login pages for Shopify, PayPal, Apple, Klarna, and banks, while streaming victim keystrokes to the attacker in real time. Active campaigns targeting Southeast Asia and the Middle East deliver the JWR client via SMS lures impersonating toll authorities, postal services, and courier companies.

Why it matters: Organizations and individuals in Southeast Asia and the Middle East face active credential and payment data theft from operators using JWR; defenders should implement email and SMS security controls, educate users on URL verification, and monitor for Cisco Talos IOCs and ClamAV signatures to detect JWR deployments on compromised domains.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Dissecting the JWR phishing framework

Cisco Talos identified JWR, an undocumented phishing framework likely derived from the Outsider phishing-as-a-service platform, that harvests payment card data, identity documents, credentials, and device fingerprints through real-time operator control. The framework uses AES-CTR encrypted WebSocket connections and Vue.js interfaces to impersonate checkout and login pages for Shopify, PayPal, Apple, Klarna, and banks, while streaming victim keystrokes to the attacker in real time. Active campaigns targeting Southeast Asia and the Middle East deliver the JWR client via SMS lures impersonating toll authorities, postal services, and courier companies.

Why it matters: Organizations and individuals in Southeast Asia and the Middle East face active credential and payment data theft from operators using JWR; defenders should implement email and SMS security controls, educate users on URL verification, and monitor for Cisco Talos IOCs and ClamAV signatures to detect JWR deployments on compromised domains.

VendorsAdobeAppleCiscoGitHubMicrosoftWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary