JokerOTP is a phishing and OTP-interception bot/platform described by authorities and researchers as a phishing-as-a-service tool used to bypass two-factor or multi-factor authentication and hijack online accounts. Its core tradecraft is automated voice phishing: the bot places calls to victims, impersonates trusted organizations or customer service, claims criminals are trying to access the victim’s account, and prompts the victim to enter the one-time password they just received. The stolen OTP or 2FA code is then used to access accounts, conduct fraudulent transactions, and in some cases change security settings to maintain access. Supporting reporting also states the platform used fake websites resembling legitimate login portals for real financial institutions. JokerOTP has been marketed and sold via Telegram, with associated license keys referenced in law-enforcement actions. Reported targets and abused services include PayPal, Venmo, Coinbase, Apple, banks, cryptocurrency exchanges, and other major service providers; the intercepted codes were used to secure online accounts and financial transactions. Authorities reported JokerOTP was used more than 28,000 times across 13 countries over a two-year period, with estimated losses of about $10 million, and one report cites theft of over £7.5 million. Law-enforcement reporting ties the tool to a three-year joint investigation by Dutch and U.K. police, including arrests of the developer, a co-developer, and an alleged distributor. High-confidence behavioral indicators from the content are automated calls impersonating trusted companies, collection of OTP/2FA codes, Telegram-based sales/licensing, and use in account takeover and fraud.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A phishing-as-a-service tool used to intercept one-time passwords (OTPs) via social engineering (including automated calls impersonating trusted companies) to hijack victim accounts; marketed via Telegram and used at scale against consumer financial/tech accounts.
A Telegram-sold automated calling bot used in social-engineering/voice phishing to trick victims into entering one-time passwords, enabling attackers to bypass 2FA and take over accounts for fraud.
A bot-based phishing/voice-social-engineering platform used to steal one-time passwords (OTPs) / 2FA codes by automatically calling victims, impersonating trusted organizations (e.g., banks/crypto exchanges), and prompting victims to enter their OTPs; also supported fake login websites to capture credentials and enable account takeover and fraud.
Phishing kit sold on Telegram designed to intercept one-time passwords (OTP), including via voice calls/social engineering to capture OTPs during account takeover attempts.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.