JWR phishing kit streams keystrokes live
Talos documents a framework whose operators watch partial card numbers appear before the victim submits anything.
SeverityHigh
2 minThreat Intelligence
Cisco Talos has published an analysis of JWR, a phishing framework built to harvest payment card data, credentials and identity documents as they are typed. Talos assesses with medium confidence that it is a variant of The Outsider, a phishing-as-a-service platform run by Chinese-speaking operators, against which the FBI conducted a takedown in June 2026.
The design detail that matters operationally is the streaming. Each input field is transmitted to the operator console as the victim fills it in, rather than on submission. An operator can therefore see a partial card number or a half-entered credential before the form is sent, and can react while the victim is still on the page.
The framework runs in two modes. Host mode holds a persistent WebSocket connection to the command server and relays instructions into an embedded iframe carrying the phishing form. Content mode is a Vue.js application rendering across 44 phishing pages and accepting more than 40 distinct operator commands.
The data set it collects is broad: card number, CVV, PIN and expiry, national identification number, passport or identity document images, two-factor codes, website and PayPal logins, and a device fingerprint. Observed campaigns arrived by SMS impersonating toll authorities, postal services and couriers across Southeast Asia and the Middle East.
Detection
- ClamAV signature Js.Phishing.JwrFramework-10060456-0.
- Snort rules SIDs 66924 through 66928.
- Operator-side messaging is written entirely in Simplified Chinese.
Live relay undercuts the usual advice to close the tab after entering something in error. By the time the reader recognises the page, the operator already holds what was typed.
Retold from Cisco Talos. This is a summary in our own words; follow the link for the original reporting.