ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Smishing Triad's Outsider Cluster Uses JWR Real-Time Phishing Kit to Steal Cards, OTPs and Bank Credentials

highPhishing & fraudexploited in the wildimportance 65
What's new: First merged summary for this story: Group-IB has publicly attributed the JWR real-time WebSocket smishing kit to the Outsider cluster of the Smishing Triad and published detection IoCs; the Unit 42 figure of 194,345 malicious domains across 136,933 root domains since January 2024 is cited as prior context on the campaign's scale.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Group-IB attributes a large-scale SMS phishing operation to the Outsider cluster within the Smishing Triad phishing-as-a-service ecosystem, using the JWR kit whose WebSocket channels stream card numbers, passwords and OTPs to operators in real time.

Group-IB linked the JWR phishing kit to an operator sub-cluster it tracks as Outsider, a customer within the broader Smishing Triad phishing-as-a-service ecosystem. Fake toll, parcel and delivery SMS messages lead victims to live phishing pages built on a Vue 2 SPA with a Web Worker, where WebSocket channels stream form inputs to an operator console before victims even submit forms. The kit supports up to 32 guided pages, wraps traffic in AES-256-CTR with keys embedded per message, rotates domains and short links (falling back to polling every two seconds), and carries WordPress or Shopify integration markers. It harvests roughly 70 PII fields, card data, PINs, OTPs, identity document images and digital wallet credentials, with three credential slots and a dedicated PayPal sub-funnel; operators can request SMS codes, PINs, extra cards or QR verification mid-session, enabling account takeover and unauthorized payments. Unit 42 previously tied 194,345 malicious domains across 136,933 root domains to the broader operation since January 2024. Defenders can hunt for /api/open/ endpoints, /webSocket/QT/ paths, JWR-prefixed storage artifacts and a hard-coded WebSocket token; Group-IB has published IoCs including storage keys, page names and WebSocket tokens.

  • Group-IB attributes the campaign to Outsider, an operator cluster operating as a customer within the Smishing Triad phishing-as-a-service ecosystem.
  • The JWR kit uses a Vue 2 SPA with a Web Worker and WebSocket channels, streaming form inputs to operators in real time before victims submit forms.
  • Kit supports up to 32 guided pages and AES-256-CTR-encrypted traffic with keys embedded per message.
  • It rotates domains and short links, falling back to polling every two seconds, and shows WordPress or Shopify integration markers.
  • Kit collects ~70 PII fields, three credential slots, card data, PINs, OTPs, identity document images and digital wallet credentials via a dedicated PayPal sub-funnel.
  • Operators can request SMS codes, PINs, extra cards or QR verification mid-session, enabling account takeover and unauthorized payments.
  • Lures include fake toll, parcel and delivery SMS messages.
  • Unit 2 previously... correction: Unit 42 tied 194,345 malicious domains across 136,933 root domains to the broader operation since January 2024.

Coverage timeline

  1. · 4h ago
    GBHackers· 65
    Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials

    Group-IB attributes large-scale smishing using the JWR real-time phishing kit to the Smishing Triad's Outsider cluster, harvesting card data, OTPs, and bank credentials.

  2. · 2h ago
    Cyber Security News· 58
    Smishing Hackers Can Watch Every Keystroke as Victims Enter Card Details and OTPs

    Group-IB details the JWR smishing kit, used by the Outsider cluster, that streams keystrokes and OTPs to fraudsters in real time via WebSocket.