A Smishing Triad operator cluster tracked as Outsider is deploying the reusable JWR phishing kit in SMS campaigns impersonating toll, delivery, payment, and account-verification services. Shortened links send targets to short-lived, brand-skinned phishing pages where a persistent WebSocket connection streams every form-field update—including payment-card details, credentials, PINs, and one-time passcodes—to operators before the victim submits the form. Operators can steer victims through up to 32 pages or in-page transitions; JWR falls back to HTTP long polling at two-second intervals when WebSockets are unavailable.
The same tooling has been linked to fraudulent Shopify storefronts promoted through malicious Google Shopping ads. A checkout redirect script routes shoppers to attacker-controlled payment pages, while Shopify Admin API order confirmations help make the transactions appear legitimate; a related Playswing kit provides separate MQTT-backed phishing infrastructure. Researchers reported more than 2,000 active fake stores, with roughly 100 added weekly. Although domains and brand templates rotate rapidly, defenders can hunt for JWR storage keys, JavaScript and page names, API and WebSocket paths, tokens, session naming, traffic patterns, and related WordPress or Shopify integration markers; extracted indicators should be validated before blocking.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
BforeAI disclosed the fraudulent Shopify-store campaign to Shopify and reported that it had received no response by September 14, 2026.
Group-IB identified the reusable JWR phishing kit in SMS-phishing activity and linked it to the Outsider operator cluster within the broader Smishing Triad ecosystem. The kit streams form-field changes, including payment-card data and OTPs, to operators through WebSockets before victims submit forms.
BforeAI published a technical report describing a campaign that used brand-impersonating Shopify stores and fraudulent Google Shopping ads to direct buyers to attacker-controlled payment pages. The report linked the operation to Outsider/JWR and Playswing phishing kits and estimated more than 2,000 active stores, with roughly 100 added weekly.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecryptika.com
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.