Dissecting the JWR phishing framework
ID: eb6d92e7-d079-5c1f-a541-845c15c1486e
STIX ID: report--eb6d92e7-d079-5c1f-a541-845c15c1486e
Feed Name: Cisco Talos
Cisco Talos identified and analyzed JWR, an undocumented, operator-driven phishing framework (likely a variant of the Outsider PhaaS) that impersonates checkout/login flows across major platforms and streams victims' keystrokes and submitted data in near real time via an AES-CTR encrypted WebSocket; the kit harvests full card data, PII, credentials, 2FA codes and device fingerprints, integrates with Shopify/WooCommerce to appear legitimate, is delivered via SMS smishing in Southeast Asia and the Middle East, and includes detailed C2 endpoints, operator instruction mappings, IOCs and detection signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
