Cisco Talos disclosed an undocumented phishing framework named JWR that supports real-time, operator-driven phishing sessions instead of simple static credential harvesting. The kit impersonates checkout and login flows for brands including Shopify, PayPal, Apple, Klarna, banks, and e-commerce storefronts, while sending victim keystrokes, device details, and browser fingerprints to command-and-control infrastructure over encrypted WebSocket connections with HTTP fallback. Talos said JWR can collect payment card data, account credentials, Social Security numbers, identity documents, passport and driver’s license images, and 2FA codes, and it includes more than 40 operator commands across 44 phishing pages.
Researchers assessed with medium confidence that JWR is a variant of The Outsider phishing-as-a-service platform because of substantial code and functional overlap. Talos also linked the framework to active smishing campaigns using toll-road, postal-service, and courier payment lures across Southeast Asia and the Middle East, and said Chinese-language operator messages indicate the activity is likely tied to Chinese-speaking threat actors within the broader phishing-as-a-service ecosystem.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos published detection coverage for JWR, including the ClamAV signature Js.Phishing.JwrFramework-10060456-0 and Snort rules 66924 through 66928.
Cisco Talos assessed with medium confidence that JWR is a variant of The Outsider phishing-as-a-service platform. The assessment was based on substantial code and functional similarities between the two client engines.
Talos observed a real-world JWR campaign delivered through SMS phishing lures impersonating toll authorities, postal services, and courier brands. The campaign targeted victims across Southeast Asia and the Middle East.
Cisco Talos identified an undocumented phishing framework internally branded as JWR by its developer. The framework supports real-time, operator-driven phishing sessions and extensive data theft from victims.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourceblog.talosintelligence.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.