logo

JWR Phishing Framework Uses Real-Time WebSocket Control and AES Encryption to Steal Banking Credentials

ID: 06229a85-ac92-54b6-a6c0-f16bffbc82e3

STIX ID: report--06229a85-ac92-54b6-a6c0-f16bffbc82e3

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-08-18

Date Updated: 2026-08-19

Author: Tushar Subhra Dutta

...
...

Cisco Talos and other researchers describe JWR, a real-time phishing framework delivered via smishing that uses persistent WebSocket connections and encrypted client traffic to let operators steer victims through multi-step fake payment/bank pages and harvest card details, credentials, OTPs, identity documents, and device cookies; the report includes delivery patterns, mitigation advice, and IoCs such as WebSocket paths, API endpoints, file paths, and detection signatures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.