Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs
ID: 35bbc9f4-af3b-5d29-9d21-209ef9d3c54d
STIX ID: report--35bbc9f4-af3b-5d29-9d21-209ef9d3c54d
Feed Name: cybersecurityNews.com
Group-IB researchers identified an active smishing campaign using the reusable JWR phishing kit that impersonates services via urgent SMS links, redirects victims to temporary pages, and streams entered data (card numbers, CVVs, OTPs, passwords) in real time to operators via a WebSocket console (with an HTTP long-poll fallback). The kit’s features — AES-CTR-wrapped messages, a WebSocket token, rotating domains, platform integration markers (WordPress/Shopify), and a long list of IoCs (page names, local storage keys, C2 endpoints, WebSocket paths, YARA/Suricata strings) — enable rapid detection and takedown but also facilitate large-scale, live-fraud attacks that can convert stolen data into immediate financial loss.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
