30
30
47
60
45
60
60
30
60
30
60
60
42
60
60
30
45
60
60
60
42
30
57
30
30
42
45
30
57
42
57
30
30
42
42
55
35
Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs
Group-IB details the JWR smishing kit, used by the Outsider cluster, that streams keystrokes and OTPs to fraudsters in real time via WebSocket.
Group-IB linked the JWR phishing kit to an operator cluster it tracks as Outsider within the broader Smishing Triad ecosystem. Fake toll, parcel, and delivery messages lead to live phishing pages that capture card numbers, passwords, and one-time passcodes before victims submit forms. The kit supports up to 32 guided pages, AES-256-CTR wrapped traffic with keys embedded per message, rotating short links and domains, and WordPress or Shopify integration markers, enabling account takeover and unauthorized payments.
58
57
30