JWR Phishing Framework Uses Real-Time WebSocket Control and AES Encryption to Steal Banking Credentials
ID: 06229a85-ac92-54b6-a6c0-f16bffbc82e3
STIX ID: report--06229a85-ac92-54b6-a6c0-f16bffbc82e3
Feed Name: cybersecurityNews.com
Threat Score
Cisco Talos and other researchers describe JWR, a real-time phishing framework delivered via smishing that uses persistent WebSocket connections and encrypted client traffic to let operators steer victims through multi-step fake payment/bank pages and harvest card details, credentials, OTPs, identity documents, and device cookies; the report includes delivery patterns, mitigation advice, and IoCs such as WebSocket paths, API endpoints, file paths, and detection signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
