Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Dissecting the JWR phishing framework

0
Medium
Published: 08/13/2026 (08/13/2026, 10:00:35 UTC)
Source: Cisco Talos

Description

Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim's session live. The victim data targeted by the actor using JWR extends well beyond payment data, encompassing identity documents, Social Security numbers, passport and driver's license images, website and PayPal credentials, 2FA codes, and full device fingerprints, all committed to the actor's server once a session ends. Talos assesses with medium confidence that the JWR phishing framework is a variant of "The Outsider," a phishing-as-a-service (PhaaS) platform, based on several similarities in the client engine scripts and functionalities of the two PhaaS platforms. Talos observed a real-world campaign delivering the JWR client via SMS lures impersonating toll authorities, and postal and courier services of several countries in Southeast Asia and the Middle East. JWR phishing framework, a likely variant of the Outsider JWR is a phishing framework capable of harvesting complete payment card data, login credentials, and personally identifiable information (PII) documents and images in real time. The client-side engine of the framework impersonates login, and checkout flows of several payment gateways, including Shopify, PayPal, Apple, Klarna, and banks, while allowing the operator to stealthily control the victim session through an AES-CTR encrypted WebSocket channel. The client engine architecture is divided into a Host Bridge module that relays commands into a phishing inline frame (iframe) and a Vue.js victim application that renders across 44 phishing pages, streams the victim's keystrokes to the actor as they are typed, and carries out more than 40 distinct instructions issued from the command-and-control (C2) console. The data exfiltration schema is a cvvform object that includes fields such as credit card number, CVV, PIN, expiry date, Social Security Number (SSN), passport or ID images, two-factor authentication (2FA) codes, website logins, PayPal credentials, and device fingerprint. Talos discovered that the JWR client engine shares significant code and functional similarities with the client of The Outsider PhaaS platform operated by the Chinese-speaking actor “Outsider Enterprise,” which was reported by external researchers . JWR client architecture and workflow Figure 1. JWR phishing framework’s client engine architecture and execution flow. The execution starts when the parent phishing webpage loads and executes the client's engine. It checks a single global flag, window.__HOST_MODE , which is set by the parent phishing page, and selects one of two execution modes. If the flag is set, the script enters Host Mode, and control passes to the Host Bridge module, an immediately invoked function expression (IIFE) that operates within the parent page, typically a replica of a legitimate checkout or account login page, relaying received details into a child iframe that contains the actual phishing form. It establishes a persistent WebSocket connection to the actor’s C2 server. If the flag is not set, the page enters Content Mode, and control passes to the Vue.js Application, an interactive front end that renders the phishing pages, collects victim input, manages the flow across 44 HTML files, and handles the actor’s instructions from the C2 server, ultimately redirecting to a custom error page after sending the data to the C2. The Content Mode of execution has three communication modes: standalone, pluginIframe, and hostIframe. In standalone mode, the application fully owns its WebSocket connection. In pluginIframe mode, it has no direct link to t…

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 10:16:10 UTC

Technical Analysis

Cisco Talos identified the JWR phishing framework, an undocumented phishing platform that impersonates login and checkout pages for services like Shopify, PayPal, Apple, Klarna, and banks. Unlike static phishing pages, JWR maintains a persistent AES-CTR encrypted WebSocket connection to the attacker’s command-and-control server, enabling real-time session steering and data capture. The client engine consists of a Host Bridge module that relays commands to an iframe containing the phishing form and a Vue.js victim application that renders phishing pages and streams victim keystrokes live. The framework collects a wide range of sensitive data including credit card numbers, CVV, PIN, expiry dates, Social Security numbers, passport and ID images, 2FA codes, website logins, PayPal credentials, and device fingerprints. Talos assesses with medium confidence that JWR is a variant of the Outsider phishing-as-a-service platform, based on significant code and functional similarities. Real-world campaigns have been observed delivering JWR via SMS lures impersonating toll authorities and postal/courier services in Southeast Asia and the Middle East.

Potential Impact

The JWR phishing framework enables attackers to harvest comprehensive sensitive information from victims in real time, including full payment card details, personally identifiable information (PII), login credentials, and two-factor authentication codes. This level of data exposure can lead to financial fraud, identity theft, account takeover, and broader privacy violations. The real-time control of victim sessions increases the effectiveness and stealth of the phishing attacks, potentially increasing victim compromise rates.

Defensive Guidance

No official patch or remediation is applicable as this is a phishing framework rather than a software vulnerability. Defenders should educate users to recognize phishing attempts, especially SMS lures impersonating toll authorities and courier services in Southeast Asia and the Middle East. Organizations should implement strong email and SMS filtering, multi-factor authentication, and monitor for suspicious login activity. Since the vendor advisory does not indicate any 'no action required' or 'already mitigated' status, these standard anti-phishing measures are recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.74,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/","fetched":true,"fetchedAt":"2026-08-13T10:16:00.479Z","wordCount":3642}

Threat ID: 6a7d9960bf8831d5390721b6

Added to database: 08/13/2026, 10:16:00 UTC

Last enriched: 08/13/2026, 10:16:10 UTC

Last updated: 08/14/2026, 01:08:05 UTC

Views: 17

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses