Dissecting the JWR phishing framework
tech
Cisco Talos has uncovered a sophisticated phishing framework called JWR that goes far beyond stealing a credential here and there. This system impersonates checkout and login pages for major payment platforms like PayPal, Apple, and Shopify, but with a twist: threat actors stay connected in real-time via encrypted channels, steering each victim's session like a puppet, capturing everything from payment card data and Social Security numbers to passport images and two-factor codes as they're typed. The framework appears to be a variant of an older phishing-as-a-service platform, and Talos observed active campaigns in Southeast Asia and the Middle East, delivered via SMS lures pretending to be postal and toll authorities — suggesting this tool is already in the wild and actively targeting real victims.
Source: https://blog.talosintelligence.com/dissecting-the-jwr-phi...
Listen to this story
Hear this and more stories in a personalized audio briefing.
Open The Chonkerton