logo

New Phishing Kit Gives Threat Actors Live View Into Attacks

ID: c0b5bd17-ddc0-5180-abe8-8a942e241075

STIX ID: report--c0b5bd17-ddc0-5180-abe8-8a942e241075

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: KnowBe4 Team

...
...

Cisco Talos researchers describe a phishing framework called “JWR” that livestreams victim interactions to attackers via an AES-CTR encrypted WebSocket, enabling real-time steering of login and checkout flows to harvest complete payment card data, credentials, PII (including SSNs and ID images), and 2FA codes. The platform is being used in widespread SMS phishing (smishing) campaigns impersonating national transport authorities, postal services, and regional courier brands across multiple countries to deceive victims with unpaid-toll and undelivered-parcel lures; Cisco Talos provides a detailed analysis at their blog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.