logo

Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs

ID: 35bbc9f4-af3b-5d29-9d21-209ef9d3c54d

STIX ID: report--35bbc9f4-af3b-5d29-9d21-209ef9d3c54d

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-09-16

Date Updated: 2026-09-16

Author: Tushar Subhra Dutta

...
...

Group-IB researchers identified an active smishing campaign using the reusable JWR phishing kit that impersonates services via urgent SMS links, redirects victims to temporary pages, and streams entered data (card numbers, CVVs, OTPs, passwords) in real time to operators via a WebSocket console (with an HTTP long-poll fallback). The kit’s features — AES-CTR-wrapped messages, a WebSocket token, rotating domains, platform integration markers (WordPress/Shopify), and a long list of IoCs (page names, local storage keys, C2 endpoints, WebSocket paths, YARA/Suricata strings) — enable rapid detection and takedown but also facilitate large-scale, live-fraud attacks that can convert stolen data into immediate financial loss.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.