Cisco Talos Finds JWR Runs Live Phishing Sessions

Cisco Talos identified JWR, an undocumented phishing framework that impersonates checkout and login pages across major payment and shopping brands using 44 phishing pages. Talos says it is likely a variant of the Outsider phishing-as-a-service platform and ties it to a real SMS lure campaign. JWR does more than wait for a form submit. It keeps an AES-CTR encrypted WebSocket open to the attacker, who can steer the victim’s session while the page is still in use, so keystrokes, 2FA codes, payment data, and identity documents can be captured before the run ends. That makes each successful lure worth more than a simple password grab. For teams that see users approve logins, enter one-time codes, or upload ID images in web flows, the exposure sits in those live sessions, not just in stolen credentials after the fact. Talos also published indicators and signatures, which makes detection possible where SMS-based phishing is already in play.

Part of the PlainSec briefing for 2026-08-13

Editions

Sources