ctipilot.ch

JWR

tool · tool:jwr-phishing-framework single-source

Phishing-as-a-service client framework, internally branded JWR by its developer and dissected by Cisco Talos on 13 August 2026. It holds an AES-CTR-encrypted WebSocket open between the victim's browser and the operator's console for the whole session, streaming keystrokes so the operator sees partial card numbers, passwords and verification codes as they are typed, and lets the operator direct the victim to an SMS, authenticator-app, PIN or two-factor verification page at the moment a one-time code is needed. It impersonates login and checkout flows for several payment gateways including Shopify, PayPal, Apple, Klarna and banks, and was observed delivered through SMS lures about toll and courier fees (Cisco Talos, 2026-08-13).

Coverage timeline
1
first 2026-08-15 → last 2026-08-15
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Related entities below
ATT&CK techniques
5
pinned v19.2 · see below

ATT&CK techniques

5 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1566.002Phishing: Spearphishing Link×1

Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems. Spearphishing with a link is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of links to download malware contained in email, instead of attaching malicious files to the email itself, to avoid defenses that may inspect email attachments. Spearphishing may also involve social engineering techniques, such as posing as a trusted source.

Evidence: 2026-08-15/jwr-phishing-framework-realtime-operator-websocket-mfa · ATT&CK page ↗

Stealth TA0005

T1622Debugger Evasion×1

Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads.

Evidence: 2026-08-15/jwr-phishing-framework-realtime-operator-websocket-mfa · ATT&CK page ↗

Credential Access TA0006

T1056.003Input Capture: Web Portal Capture×1

Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service.

Evidence: 2026-08-15/jwr-phishing-framework-realtime-operator-websocket-mfa · ATT&CK page ↗

T1111Multi-Factor Authentication Interception×1

Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources. Use of MFA is recommended and provides a higher level of security than usernames and passwords alone, but organizations should be aware of techniques that could be used to intercept and bypass these security mechanisms.

Evidence: 2026-08-15/jwr-phishing-framework-realtime-operator-websocket-mfa · ATT&CK page ↗

Discovery TA0007

T1622Debugger Evasion×1

Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads.

Evidence: 2026-08-15/jwr-phishing-framework-realtime-operator-websocket-mfa · ATT&CK page ↗

Collection TA0009

T1056.003Input Capture: Web Portal Capture×1

Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service. For example, a compromised login page may log provided user credentials before logging the user in to the service.

Evidence: 2026-08-15/jwr-phishing-framework-realtime-operator-websocket-mfa · ATT&CK page ↗

Command and Control TA0011

T1071.001Application Layer Protocol: Web Protocols×1

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.

Evidence: 2026-08-15/jwr-phishing-framework-realtime-operator-websocket-mfa · ATT&CK page ↗

Story timeline

  1. 2026-08-15JWR: a phishing kit that puts a live operator on an encrypted WebSocket into the victim's session, reading card and code digits as they are typed and choosing which one-time-code channel to demand
    active-threatsTalos dissects a phishing-as-a-service framework whose console streams keystrokes live and prompts for SMS, app or PIN verification on demand

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • active-threats1

Source distribution

  • blog.talosintelligence.com1 (100%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about JWR (1)

2026-08-15 · view entry permalink →

NOTABLENATOB2

JWR: a phishing kit that puts a live operator on an encrypted WebSocket into the victim's session, reading card and code digits as they are typed and choosing which one-time-code channel to demand

Cisco Talos published a dissection on 2026-08-13 of a phishing framework its developer brands "JWR", and assesses with medium confidence that it is a variant of "The Outsider", a phishing-as-a-service platform, based on several similarities in the client engine scripts and functionalities of the two platforms (Cisco Talos, 2026-08-13). The kit's client engine impersonates login and checkout flows of several payment gateways, including Shopify, PayPal, Apple, Klarna and banks, rendering across dozens of distinct phishing pages. Talos reports operator-facing status messages written entirely in Simplified Chinese, which it states indicates a Chinese-speaking operator, and observed a real-world campaign delivering the kit through SMS lures about toll or road-pricing fees and postal or courier fees, carrying a link (Cisco Talos, 2026-08-13).

The architectural change from an ordinary credential-harvesting page is the point of the research. JWR keeps an AES-CTR-encrypted WebSocket open between the victim's browser and the operator's console for the duration of the session, and streams every input field's keystrokes live: the console shows "partial card numbers, partial passwords, and partial verification codes as the victim types, without needing to wait for the victim to click any submit button" (Cisco Talos, 2026-08-13). That inverts the economics of one-time codes. A stolen code from a logged form is worth whatever remains of its validity window; a code read as it is typed, by an operator who is simultaneously driving a real session on the genuine site, is worth a completed transaction. Talos documents the mechanism explicitly: once the operator accepts the entered card data, "the operator sends one of the instructions: to_sms, to_2fa, to_pin, or to_app, directing the victim to a verification page to confirm their identity with a one-time code." The operator chooses which verification channel to demand, in real time, based on what the victim's bank actually uses — a rejected code re-prompts, an accepted one proceeds and the victim is redirected to the real site. A separate instruction lets the operator inject a code of their own choosing into the page without any victim-visible navigation.

Two further details bear on how easily this is caught. The framework carries an anti-analysis guard that "performs a self-referential .toString().search() call against a backtracking regex" to detect whether a debugger has attached and modified the function's apparent source (Cisco Talos, 2026-08-13), alongside decoy variables scattered specifically to mislead static analysis. And the Shopify integration is built to defeat origin-based judgement: the kit derives its WebSocket connection's base address from a legitimate signed parameter that Shopify itself passes between checkout steps, so the channel appears to originate from a plausible checkout domain while also letting the fake cart reproduce the victim's real products, quantities and totals. Talos compared JWR against three other phishing kits from the same ecosystem and found no shared code implementation despite behavioural similarity, which places this in a lineage of tradecraft rather than a shared codebase. Talos ships detection coverage for the threat through its own products.

Triage: a payment page legitimately opens outbound connections, so connection volume is not the discriminator. What separates this from a genuine checkout is the shape and persistence of the channel — a long-lived, bidirectional encrypted WebSocket opened immediately on page load and held for the duration of form entry, carrying traffic in both directions while the user types, against a page presenting a payment brand. Talos is explicit that the origin is deliberately engineered to look plausible for the Shopify path, so domain reputation alone will not separate the two; the behaviour of the channel will.

Talos assesses with medium confidence that the JWR phishing framework is a variant of "The Outsider," a phishing-as-a-service (PhaaS) platform, based on several similarities in the client engine scripts and functionalities of the two PhaaS platforms.

Each input element in the phishing form is transmitted to the actor's console, allowing the actor to view partial card numbers, partial passwords, and partial verification codes as the victim types, without needing to wait for the victim to click any submit button.

the operator sends one of the instructions: to_sms, to_2fa, to_pin, or to_app, directing the victim to a verification page to confirm their identity with a one-time code.

The client-side engine of the framework impersonates login, and checkout flows of several payment gateways, including Shopify, PayPal, Apple, Klarna, and banks

Cisco Talos observed an attacker utilizing an SMS phishing technique, sending SMS related to toll or road-pricing fees, postal or courier fees lures that contain a malicious URL targeting potential victims.

Cisco Talos 2026-08-13
threat15 Aug 05:18Zsingle-sourceOpen finding ↗
Sources: Cisco Talos